CVE-2018-20824
30Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 38%
exploitation probability
38%top 2% of all CVEs
observed exploitation
nono source reports it
The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter.
Affected products
Atlassian · Jira