Description
The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote attackers with Administrator permissions to gain remote code execution via a template injection vulnerability through the use of a crafted PUT request.
Remediation
References
Related Vulnerabilities
phpMyFAQ Improper Privilege Management Vulnerability (CVE-2023-1762)
MySQL CVE-2018-3145 Vulnerability (CVE-2018-3145)
SharePoint CVE-2020-1460 Vulnerability (CVE-2020-1460)
WordPress Plugin Custom Login Page Customizer-LoginPress Multiple Vulnerabilities (1.1.13)
WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth Security Bypass (2.9.2)