Description
The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability via the name of a custom field.
Remediation
References
Related Vulnerabilities
Drupal Core 8.8.x Arbitrary File Overwrite (8.8.0 - 8.8.12)
WordPress Plugin Adblock Blocker Arbitrary File Upload (0.0.1)
Liferay Portal Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-10795)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-3810)