Description
A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that allows attackers with Job/Configure and/or Job/Create permission to create an item name containing JavaScript that would be executed in another user's browser when that other user performs some UI actions.
Remediation
References
Related Vulnerabilities
WordPress Other Vulnerability (CVE-2006-4743)
WordPress Plugin Unlimited PopUps SQL Injection (4.5.3)
WordPress Plugin Timber Cross-Site Scripting (1.2.2)
WordPress Plugin Testimonial Slider Cross-Site Scripting (1.2.1)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-4283)