Description
jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in search suggestions due to improperly escaping users with less-than and greater-than characters in their names (SECURITY-388).
Remediation
References
Related Vulnerabilities
MediaWiki Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-9476)
Magento Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2019-8235)
WordPress Plugin Social Sharing-Sassy Social Share Cross-Site Scripting (3.3.39)
WordPress Plugin Redirection for Contact Form 7 Multiple Vulnerabilities (2.3.3)
WordPress Plugin blogVault Real-time Backup PHP Object Injection (1.44)