5.4
CVSSv3

CVE-2023-28679

Published: 02/04/2023 Updated: 08/04/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Jenkins Mashup Portlets Plugin 1.1.2 and previous versions provides the "Generic JS Portlet" feature that lets a user populate a portlet using a custom JavaScript expression, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by authenticated attackers with Overall/Read permission.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins mashup portlets