PT-2020-14727 · Atlassian · Gantt-Chart For Jira
Published
2020-08-04
·
Updated
2020-08-06
·
CVE-2020-15944
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Gantt-Chart for Jira versions prior to 5.5.5
Description
The issue is related to missing validation of user input, making it susceptible to a persistent XSS attack. An attacker must be authenticated to exploit this vulnerability, and they can embed attack vectors in the dashboard of other users.
Recommendations
For versions prior to 5.5.5, update to version 5.5.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the Gantt-Chart module to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gantt-Chart For Jira