contact-administrators

1 article
sort: new top best
clear filter
0 7/10

Two well-known but still exploitable RCE vulnerabilities in Atlassian products: CVE-2019-11581 in Jira's ContactAdministrators form via Java expression injection, and CVE-2019-3396 in Confluence's Widget Connector macro allowing arbitrary file access and command execution via the _template parameter. The article provides step-by-step exploitation techniques with proof-of-concept payloads.

CVE-2019-11581 CVE-2019-3396 Jira Confluence Atlassian Valeriy Shevchenko Knownsec 404 ruvlol
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details