CVE-2023-36662

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
26/06/2023
Last modified:
06/07/2023

Description

The TechTime User Management components for Atlassian products allow stored XSS on the Bulk User Actions page. This affects User Management for Jira 2.0.0 through 2.17.1, User Management for Confluence 2.0.0 through 2.15.24, and User Management for Bitbucket 2.2.2 through 2.15.24.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:techtime:user_management:*:*:*:*:*:confluence:*:* 2.0.0 (including) 2.15.24 (including)
cpe:2.3:a:techtime:user_management:*:*:*:*:*:jira:*:* 2.0.0 (including) 2.17.1 (including)
cpe:2.3:a:techtime:user_management:*:*:*:*:*:bitbucket:*:* 2.2.2 (including) 2.15.24 (including)