CVE-2023-26256
high · 7.5A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjFooterNavigationConfig endpoint, it is possible to traverse and read the file system.
7.5
CVSS
11.6%
EPSS (exploit prob.)
96th
EPSS percentile
2023-02-28
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| stagil | stagil_navigation | < 2.0.52 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/1nters3ct/CVEs/blob/main/CVE-2023-26256.md
- https://marketplace.atlassian.com/apps/1216090/stagil-navigation-for-jira-menus-themes?tab=overview&hosting=cloud
- https://github.com/1nters3ct/CVEs/blob/main/CVE-2023-26256.md
- https://marketplace.atlassian.com/apps/1216090/stagil-navigation-for-jira-menus-themes?tab=overview&hosting=cloud
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-26256