Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Bartłomiej Florek

#44268of 56,334
6.5Total CVSS
Vulnerabilities · 1
PT-2025-11218
6.5
2025-03-13
Unknown · Plugin People Enterprise Mail Handler · CVE-2025-25363
Name of the Vulnerable Software and Affected Versions: The Plugin People Enterprise Mail Handler for Jira Data Center versions prior to 4.1.69-dc Description: An authenticated stored cross-site scripting issue allows attackers with Administrator privileges to execute arbitrary Javascript in the context of a user's browser by injecting a crafted payload into the HTML field of a template. Recommendations: For versions prior to 4.1.69-dc, update to version 4.1.69-dc or later to resolve the issue. As a temporary workaround, consider restricting access to the template HTML field to minimize the risk of exploitation.