CVE-2020-14166: Atlassian Jira Service Desk
Medium severity, CVSS 4.8. EPSS: 1.9% chance of exploitation in the next 30 days.
The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remote attackers with project administrator privileges to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by uploading a html file.
Affected products
- Atlassian Jira Service Desk: before 4.10.0 (fixed in 4.10.0)
Published 2020-07-01. Last modified 2026-06-17.