漏洞描述 版本7.6.6之前的Atlassian JiraConfluence、版本7.7.4之前的版本7.7.0、版本7.8.4之前的7.8.0以及版本7.9.2之前的7.9.0,允许远程攻击者在指定无效值时,通过自定义字段的错误消息中的跨站点脚本漏洞注入任意HTML或JavaScript。
相关漏洞推荐 POC CVE-2017-5983: JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE) Atlassian Jira Software Data Center And Server 需授权 路径遍历漏洞 CVE-2019-3396: Atlassian Confluence Path Traversal Atlassian Confluence /json/setup-restore.action 文件上传漏洞(CVE-2023-22518) POC CVE-2015-8399: Atlassian Confluence <5.8.17 - Information Disclosure POC CVE-2017-9506: Atlassian Jira IconURIServlet - Cross-Site Scripting/Server-Side Request Forgery POC CVE-2018-20824: Atlassian Jira WallboardServlet <7.13.1 - Cross-Site Scripting POC CVE-2018-5230: Atlassian Jira Confluence - Cross-Site Scripting POC CVE-2019-11580: Atlassian Crowd and Crowd Data Center - Unauthenticated Remote Code Execution POC CVE-2019-11581: Atlassian Jira Server-Side Template Injection POC CVE-2019-3396: Atlassian Confluence Server - Path Traversal POC CVE-2019-3398: Atlassian Confluence Download Attachments - Remote Code Execution POC CVE-2019-3401: Atlassian Jira <7.13.3/8.0.0-8.1.1 - Incorrect Authorization