Description
Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and greater-than characters.
Remediation
References
Related Vulnerabilities
WordPress 4.3.x Multiple Vulnerabilities (4.3 - 4.3.22)
MySQL Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2016-6664)
MediaWiki Improper Input Validation Vulnerability (CVE-2017-0366)
WordPress Plugin GorillaForms-Custom Contact Forms Unspecified Vulnerability (2.0.3)
WordPress Plugin Opal Estate Cross-Site Request Forgery (1.6.11)