Description
Jenkins 2.423 and earlier, LTS 2.414.1 and earlier does not escape the value of the 'caption' constructor parameter of 'ExpandableDetailsNote', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control this parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Contact Form Email Cross-Site Scripting (1.0)
MyBB Cryptographic Issues Vulnerability (CVE-2010-4626)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3838)
WordPress Plugin WP Statistics Multiple Unspecified Vulnerabilities (9.6.5)
XWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2023-34466)