PT-2023-22700 · Unknown · Teamlead Reminder

Sven Schlüter

+1

·

Published

2023-06-16

·

Updated

2024-12-12

·

CVE-2023-30453

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Teamlead Reminder plugin for Jira versions through 2.6.5
Description The issue allows for persistent XSS via the message parameter. This can lead to malicious scripts being executed on the client-side, potentially compromising user data or taking control of user sessions.
Recommendations For versions through 2.6.5, consider disabling the plugin until a patch is available to prevent exploitation. Restrict access to the plugin's functionality to minimize the risk of XSS attacks. Avoid using the message parameter in the affected plugin until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-30453

Affected Products

Teamlead Reminder