CVE-2018-1000113
13.03.2018, 13:29
A cross-site scripting vulnerability exists in Jenkins TestLink Plugin 2.12 and earlier in TestLinkBuildAction/summary.jelly and others that allow an attacker who can control e.g. TestLink report names to have Jenkins serve arbitrary HTML and JavaScript
Vendor | Product | Version |
---|---|---|
jenkins | testlink | 𝑥 ≤ 3.12 |
𝑥
= Vulnerable software versions