Description
The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.
Remediation
References
Related Vulnerabilities
Mailman Other Vulnerability (CVE-2004-1177)
Jboss EAP Out-of-bounds Read Vulnerability (CVE-2019-0210)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17307)
WordPress Plugin Shortcode Factory Local File Inclusion (2.7)
Oracle Application Server Other Vulnerability (CVE-2005-3449)