Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-25764


Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generated during template rendering, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or change custom email templates.


Published

2023-02-15T14:15:13.617

Last Modified

2025-03-19T17:15:38.530

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins email_extension < 2.93.1 Yes

References