- Description
- The TechTime User Management components for Atlassian products allow stored XSS on the Bulk User Actions page. This affects User Management for Jira 2.0.0 through 2.17.1, User Management for Confluence 2.0.0 through 2.15.24, and User Management for Bitbucket 2.2.2 through 2.15.24.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 5.4
- Impact score
- 2.7
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- nvd@nist.gov
- CWE-79
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:techtime:user_management:*:*:*:*:*:confluence:*:*",
"vulnerable": true,
"matchCriteriaId": "EDAB4E04-2ABF-4353-8CF7-25F790F28D68",
"versionEndIncluding": "2.15.24",
"versionStartIncluding": "2.0.0"
},
{
"criteria": "cpe:2.3:a:techtime:user_management:*:*:*:*:*:jira:*:*",
"vulnerable": true,
"matchCriteriaId": "6516573A-D029-48B8-9D32-36AFFAAF70ED",
"versionEndIncluding": "2.17.1",
"versionStartIncluding": "2.0.0"
},
{
"criteria": "cpe:2.3:a:techtime:user_management:*:*:*:*:*:bitbucket:*:*",
"vulnerable": true,
"matchCriteriaId": "7BFE3E31-0974-485B-AD3D-C89782F0E975",
"versionEndIncluding": "2.15.24",
"versionStartIncluding": "2.2.2"
}
],
"operator": "OR"
}
]
}
]