NA

CVE-2023-35145

Published: 14/06/2023 Updated: 23/06/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Jenkins Sonargraph Integration Plugin 5.0.1 and previous versions does not escape the file path and the project name for the Log file field form validation, resulting in a stored cross-site scripting vulnerability exploitable by attackers with Item/Configure permission.

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins sonargraph integration

Vendor Advisories

DescriptionThe MITRE CVE dictionary describes this issue as: Jenkins Sonargraph Integration Plugin 501 and earlier does not escape the file path and the project name for the Log file field form validation, resulting in a stored cross-site scripting vulnerability exploitable by attackers with Item/Configure permission ...