CVE-2018-20241: XSS
The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the wbuser parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-20241?
CVE-2018-20241 is a vulnerability in Atlassian Fisheye and Crucible that allows remote attackers to inject arbitrary HTML or JavaScript via a cross-site scripting (XSS) vulnerability.
How does CVE-2018-20241 affect Atlassian Fisheye and Crucible?
CVE-2018-20241 affects Atlassian Fisheye and Crucible versions up to 4.7.0.
What is the severity of CVE-2018-20241?
CVE-2018-20241 has a severity rating of medium (5.4).
How can remote attackers exploit CVE-2018-20241?
Remote attackers can exploit CVE-2018-20241 by injecting arbitrary HTML or JavaScript through the wbuser parameter in the Edit upload resource for a review in Atlassian Fisheye and Crucible.
Are there any references for CVE-2018-20241?
Yes, references for CVE-2018-20241 can be found at the following links: [SecurityFocus](http://www.securityfocus.com/bid/107128), [Atlassian Issue Tracker - CRUC-8380](https://jira.atlassian.com/browse/CRUC-8380), [Atlassian Issue Tracker - FE-7162](https://jira.atlassian.com/browse/FE-7162).