CVE-2018-1000113

MEDIUM5.4EPSS 0.06%

Stored cross-site scripting vulnerability in Jenkins TestLink Plugin

Published: 5/14/2022Modified: 2/16/2024
Also known as:GHSA-3rrg-p8xc-3457

Description

A cross-site scripting vulnerability exists in Jenkins TestLink Plugin 2.12 and earlier in TestLinkBuildAction/summary.jelly and others that allow an attacker who can control e.g. TestLink report names to have Jenkins serve arbitrary HTML and JavaScript

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.4CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References (2)