CVE-2018-20240: XSS
The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-20240?
CVE-2018-20240 is a vulnerability in Atlassian Fisheye and Crucible before version 4.7.0 that allows remote attackers to inject arbitrary HTML or JavaScript via a cross-site scripting (XSS) vulnerability.
How does CVE-2018-20240 affect Atlassian Crucible and FishEye?
CVE-2018-20240 affects Atlassian Crucible and FishEye versions prior to 4.7.0.
What is the severity level of CVE-2018-20240?
The severity level of CVE-2018-20240 is medium, with a CVSS score of 4.8.
How can remote attackers exploit CVE-2018-20240?
Remote attackers can exploit CVE-2018-20240 by injecting arbitrary HTML or JavaScript code through the href parameter in the administrative linker functionality.
Are there any references for CVE-2018-20240?
Yes, you can find references for CVE-2018-20240 at the following links: [1] http://www.securityfocus.com/bid/107128, [2] https://jira.atlassian.com/browse/CRUC-8381, [3] https://jira.atlassian.com/browse/FE-7163.