Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not implement any restrictions for the URL rendering a formatted preview of markup passed as a query parameter, resulting in a reflected cross-site scripting (XSS) vulnerability if the configured markup formatter does not prohibit unsafe elements (JavaScript) in markup.
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2007-1886)
WordPress Plugin CIP4 Folder Download Widget Local File Inclusion (1.10)
WordPress Plugin SimpleFlickr Cross-Site Request Forgery (3.0.3)
WordPress Plugin WordPress Email Marketing-WP Email Capture Multiple Vulnerabilities (3.9.3)
WordPress 4.3.x Denial of Service Vulnerability (4.3 - 4.3.15)