5.4
CVSSv3

CVE-2021-21700

Published: 12/11/2021 Updated: 22/11/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Jenkins Scriptler Plugin 3.3 and previous versions does not escape the name of scripts on the UI when asking to confirm their deletion, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by exploitable by attackers able to create Scriptler scripts.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins scriptler