CVE-2023-25763

Severity
5.4MEDIUM
EPSS
11.7%
top 6.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 15

Description

Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control affected fields.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

🔴Vulnerability Details

3
CVEList
CVE-2023-25763: Jenkins Email Extension Plugin 22023-02-15
OSV
Cross-site Scripting in Jenkins Email Extension Plugin2023-02-15
GHSA
Cross-site Scripting in Jenkins Email Extension Plugin2023-02-15

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2023-02-152023-02-15
CVE-2023-25763 (MEDIUM CVSS 5.4) | Jenkins Email Extension Plugin 2.93 | cvebase.io