Description
Jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in parameter names and descriptions (SECURITY-353). Users with the permission to configure jobs were able to inject JavaScript into parameter names and descriptions.
Remediation
References
Related Vulnerabilities
WordPress Plugin Contact Bank-Contact Form Builder for WordPress Cross-Site Scripting (3.0.30)
SharePoint CVE-2022-21987 Vulnerability (CVE-2022-21987)
Jenkins Incorrect Authorization Vulnerability (CVE-2018-1999047)
Moodle 7PK - Security Features Vulnerability (CVE-2015-5331)
WordPress Plugin Calendar Event Multi View Multiple SQL Injection Vulnerabilities (1.1.7)