CVE-2023-36662
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
26/06/2023
Last modified:
06/07/2023
Description
The TechTime User Management components for Atlassian products allow stored XSS on the Bulk User Actions page. This affects User Management for Jira 2.0.0 through 2.17.1, User Management for Confluence 2.0.0 through 2.15.24, and User Management for Bitbucket 2.2.2 through 2.15.24.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:techtime:user_management:*:*:*:*:*:confluence:*:* | 2.0.0 (including) | 2.15.24 (including) |
| cpe:2.3:a:techtime:user_management:*:*:*:*:*:jira:*:* | 2.0.0 (including) | 2.17.1 (including) |
| cpe:2.3:a:techtime:user_management:*:*:*:*:*:bitbucket:*:* | 2.2.2 (including) | 2.15.24 (including) |
To consult the complete list of CPE names with products and versions, see this page



