Description
A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages.
Remediation
References
Related Vulnerabilities
PrestaShop CVE-2023-39529 Vulnerability (CVE-2023-39529)
OpenSSL Improper Authentication Vulnerability (CVE-2009-0653)
WordPress Plugin Theme Tuner 'tt-abspath' Parameter Remote File Include (0.7)
MySQL CVE-2014-6551 Vulnerability (CVE-2014-6551)
WordPress Plugin Disable Feeds Unspecified Vulnerability (1.4)