Description
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3.
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-2000-0025)
WordPress Plugin UPM Polls 'qid' Parameter SQL Injection (1.0.3)
TYPO3 Improper Input Validation Vulnerability (CVE-2009-0258)
WordPress 4.9.x Prototype Pollution (4.9 - 4.9.19)
WordPress Plugin verwei.se-WordPress-Twitter Cross-Site Scripting (1.0.2)