CVE-2018-5229
16.07.2018, 13:29
The NotificationRepresentationFactoryImpl class in Atlassian Universal Plugin Manager before version 2.22.9 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of user submitted add-on names.
Vendor | Product | Version |
---|---|---|
atlassian | universal_plugin_manager | 𝑥 < 2.22.9 |
𝑥
= Vulnerable software versions