GHSA-9w23-w757-mvv8
HIGHCVE-2022-30968Jenkins vboxwrapper Plugin 1.3 and earlier does not escape the name and description of VBox node parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. This results in stored cross-site scripting (XSS) vulnerabilities exploitable by attackers with Item/Configure permission.
- Affected
- <= 1.3
- Fixed in
- not stated
- Weakness
- CWE-79
- Published
- 2022-05-18
- Source
- github