Description
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3.
Remediation
References
Related Vulnerabilities
WordPress Plugin Widgets for WooCommerce Products on Elementor Security Bypass (1.0.5)
Magento Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2019-7854)
Grafana Incorrect Authorization Vulnerability (CVE-2021-28146)
Liferay Portal Cleartext Storage of Sensitive Information Vulnerability (CVE-2021-33325)