3.5
CVSSv2

CVE-2018-1000113

Published: 13/03/2018 Updated: 04/04/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

A cross-site scripting vulnerability exists in Jenkins TestLink Plugin 2.12 and previous versions in TestLinkBuildAction/summary.jelly and others that allow an attacker who can control e.g. TestLink report names to have Jenkins serve arbitrary HTML and JavaScript

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins testlink