Description
The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.
Remediation
References
Related Vulnerabilities
SugarCRM Gain Sensitive Information Vulnerability (CVE-2004-1226)
WordPress 3.7.x Multiple Vulnerabilities (3.7 - 3.7.12)
WordPress Other Vulnerability (CVE-2007-1894)
Apache Tomcat Incorrect Default Permissions Vulnerability (CVE-2020-8022)
OpenSSL Improper Input Validation Vulnerability (CVE-2013-4353)