← Back to browse · API

CVE-2023-26255

Severity
HIGH
CVSS
7.5
EPSS
0.47199
Risk score
46.52
CISA KEV
No
PoC
No
Published
2023-02-28
Modified
2025-03-18
First seen
2026-08-07
Aliases
EUVD-2023-30079, GHSA-5GH3-4WWV-VGPW
Products
n/a:n/a n/a
Sources
euvd EUVD-2023-30079

Description

An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjCustomDesignConfig endpoint, it is possible to traverse and read the file system.

References