Description
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3.
Remediation
References
Related Vulnerabilities
CubeCart Improper Input Validation Vulnerability (CVE-2012-0865)
WordPress Plugin Social Media Widget Serving Spam (4.0)
WordPress Plugin Wordfence Security-Firewall & Malware Scan Cross-Site Scripting (5.1.2)
WordPress Plugin MasterStudy LMS-for Online Courses and Education Information Disclosure (3.2.10)