Atlassian Jira Template Injection Vulnerability Remote OS Command Injection Exploit

This module exploits a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. The ContactAdministrators action doesn't require authentication but it's not enabled by default. The SendBulkMail does require authentication and the "JIRA Administrators" access level.
Exploit Platform
Product Name