Description
Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
Remediation
References
Related Vulnerabilities
WordPress Plugin SportsPress-Sports Club & League Manager Cross-Site Scripting (2.7.1)
WordPress Plugin SlideDeck 2 Lite Responsive Content Slider Cross-Site Scripting (2.3.18)
WordPress Plugin Disable Comments Cross-Site Request Forgery (1.0.3)
Drupal Core 4.7.x Form Action Attribute Injection (4.7.0 - 4.7.3)