← Back to CVE List

CVE-2018-20232

Published: 2019-02-13T18:29Z
Last Modified: 2024-11-21T04:01Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the rendering of retrieved content from a url location that could be manipulated by the up_projectid widget preference setting. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt