Description
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.
Remediation
References
Related Vulnerabilities
WordPress Plugin Booked-Appointment Booking for WordPress Security Bypass (2.2.5)
WordPress Plugin WP Font Awesome Cross-Site Scripting (1.7.8)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1000398)
WordPress Plugin Translate WordPress with GTranslate Cross-Site Scripting (2.8.51)