CVE-2018-13403: XSS
The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.12.4, and from version 7.13.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a saved filter when displayed on a Jira dashboard.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13403?
CVE-2018-13403 is classified as a high severity vulnerability due to its potential for remote code execution via XSS.
How do I fix CVE-2018-13403?
You can fix CVE-2018-13403 by upgrading Atlassian Jira to version 7.6.10 or later, or versions 7.12.4 and above.
What types of attacks can CVE-2018-13403 facilitate?
CVE-2018-13403 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary HTML or JavaScript.
Which software versions are affected by CVE-2018-13403?
CVE-2018-13403 affects Atlassian Jira versions prior to 7.6.10, versions from 7.7.0 to 7.12.3, and versions from 7.13.0 to 7.13.1.
Can CVE-2018-13403 be exploited without user interaction?
Yes, CVE-2018-13403 can be exploited without user interaction, making it particularly dangerous for users of affected Jira installations.