CVE-2013-5319: XSS
Published Aug 20, 2013
·Updated
Cross-site scripting (XSS) vulnerability in secure/admin/user/views/deleteuserconfirm.jsp in the Admin Panel in Atlassian JIRA before 6.0.5 allows remote attackers to inject arbitrary web script or HTML via the name parameter to secure/admin/user/DeleteUser!default.jspa.
Affected Software
5 affected components
Atlassian Jira<=6.0.4
Atlassian Jira=6.0
Atlassian Jira=6.0.1
Atlassian Jira=6.0.2
Atlassian Jira=6.0.3
Event History
Aug 20, 2013
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5319?
CVE-2013-5319 has a medium severity rating as it allows remote attackers to perform cross-site scripting attacks.
2
How do I fix CVE-2013-5319?
To fix CVE-2013-5319, update Atlassian JIRA to version 6.0.5 or later.
3
What type of vulnerability is CVE-2013-5319?
CVE-2013-5319 is a cross-site scripting (XSS) vulnerability.
4
Which versions of Atlassian JIRA are affected by CVE-2013-5319?
CVE-2013-5319 affects Atlassian JIRA versions up to and including 6.0.4.
5
What impact does CVE-2013-5319 have on users?
CVE-2013-5319 can allow attackers to inject arbitrary web scripts or HTML, potentially compromising user sessions.