Jenkins Scriptler Plugin 3.3 and... CVE-2021-21700

3.5 AV AC AU C I A
发布: 2021-11-12
修订: 2024-11-21

Jenkins Scriptler Plugin 3.3 and earlier does not escape the name of scripts on the UI when asking to confirm their deletion, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by exploitable by attackers able to create Scriptler scripts.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息