vulnerability

Atlassian JIRA: Stored XSS vulnerability in UpdateFieldJson.jspa (CVE-2012-1500)

Severity
4
CVSS
(AV:N/AC:M/Au:S/C:N/I:P/A:N)
Published
Feb 13, 2020
Added
Feb 23, 2023
Modified
Feb 24, 2023

Description

Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4.3 and GreenHopper before 5.9.8 allows an attacker to inject arbitrary script code.

Solution

atlassian-jira-upgrade-4_4_3
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.