Description
Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and before version 7.11.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the epic colour field of an issue while an issue is being moved.
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-2805 Vulnerability (CVE-2019-2805)
MySQL CVE-2013-1555 Vulnerability (CVE-2013-1555)
Apache version up to 1.3.33 htpasswd local overflow
WordPress Plugin Amministrazione Trasparente Cross-Site Request Forgery (7.1)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4401)