Description
The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jql parameter.
Remediation
References
Related Vulnerabilities
PHP Numeric Errors Vulnerability (CVE-2010-4409)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4289)
WordPress Plugin Profile Extra Fields by BestWebSoft Cross-Site Scripting (1.0.7)
WordPress Plugin Rich Widget Arbitrary File Upload (0.2.4)
Squid Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-18679)