Description
The attachment download resource in Atlassian Jira Server and Data Center The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a rdf content type.
Remediation
References
Related Vulnerabilities
WordPress Plugin Broken Link Manager SQL Injection (0.6.5)
WordPress Plugin Improved Product Options for WooCommerce Security Bypass (5.2.0)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-4298)
WordPress Plugin Flickr Justified Gallery Cross-Site Scripting (3.3.6)