Description
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including CsvFieldMappingsPage.jspa and ImporterValueMappingsPage.jspa) via a Cross-Site Request Forgery (CSRF) vulnerability in the jira-importers-plugin. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.
Remediation
References
Related Vulnerabilities
WordPress Plugin Responsive Slider-Image Slider-Slideshow for WordPress SQL Injection (2.8.6)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-1133)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4588)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-2771)
Apache Tomcat Improper Authentication Vulnerability (CVE-2013-2067)