S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-26255 Scanner

Detects 'Path Traversal' vulnerability in STAGIL Navigation plugin for Jira affects v. before 2.0.52.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-26255
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjCustomDesignConfig endpoint, it is possible to traverse and read the file system.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

STAGIL Navigation for Jira - Menu & Themes is a plugin used to customize the menu and user interface themes of the Jira software. This plugin is particularly useful for organizations that have customized their Jira installations and need to maintain a consistent design throughout the application. It enables administrators to add or remove menu items and customize the look and feel of the interface without needing any programming experience. 

CVE-2023-26255 is a severe security flaw detected in the STAGIL Navigation plugin before version 2.0.52. It is an unauthenticated path traversal vulnerability that can be exploited by an attacker to read sensitive files. By injecting a specially crafted filename parameter to the snjCustomDesignConfig endpoint, an attacker can traverse the file system and read any files that the Jira application's user account has access to. 

Exploiting the CVE-2023-26255 vulnerability can result in a range of consequences depending on the files accessed. If sensitive data such as user credentials, financial records, or sensitive company information is accessed, it can lead to severe data breaches and reputational damage. Attackers can also potentially use this vulnerability to gain access to other systems and escalate their attack. 

Thanks to the pro features of the s4e.io platform, individuals and organizations can easily and quickly learn about vulnerabilities in their digital assets. The platform offers comprehensive vulnerability scanning, threat detection, and remediation services, enabling users to maintain the security and integrity of their digital assets. With its cutting-edge technology and advanced security features, s4e.io is the ideal solution for preventing and mitigating cybersecurity threats.

 

REFERENCES

Solution Advice

There are several precautions that can be taken to protect against this vulnerability, including:

  • Updating the STAGIL Navigation plugin to the latest version (2.0.52 or higher)
  • Implementing access control measures to restrict access to sensitive files and directories
  • Regularly monitoring file-system access logs for suspicious activity
  • Conducting regular vulnerability assessments to identify and fix security flaws

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-26255 scanner - Path Traversal vulnerability in STAGIL Navigation plugin for Jira | S4E