Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-20143
HistoryMar 01, 2022 - 12:00 a.m.

JetBrains YouTrack Cross-Site Scripting Vulnerability (CNVD-2022-20143)

2022-03-0100:00:00
China National Vulnerability Database
www.cnvd.org.cn
11

0.001 Low

EPSS

Percentile

22.7%

JetBrains YouTrack is a browser-based bug tracking and project management software from JetBrains Czech Republic. A cross-site scripting vulnerability exists in versions prior to JetBrains YouTrack 2021.4.31698, which stems from a lack of data validation filtering of user-supplied data and output on the Notification templates page, which could be exploited to execute JavaScript code on the client-side execution of JavaScript code.

CPENameOperatorVersion
jetbrains youtracklt2021.4.31698

0.001 Low

EPSS

Percentile

22.7%

Related for CNVD-2022-20143