Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and before version 7.11.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the epic colour field of an issue while an issue is being moved.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published: 2018-08-28T13:00:00Z

Updated: 2024-09-16T16:42:34.901Z

Reserved: 2018-07-06T00:00:00

Link: CVE-2018-13395

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-08-28T12:29:00.353

Modified: 2024-11-21T03:47:01.240

Link: CVE-2018-13395

cve-icon Redhat

No data.