CVE-2025-25363

An authenticated stored cross-site scripting (XSS) vulnerability in The Plugin People Enterprise Mail Handler for Jira Data Center (JEMH) before v4.1.69-dc allows attackers with Administrator privileges to execute arbitrary Javascript in context of a user's browser via injecting a crafted payload into the HTML field of a template.
Configurations

Configuration 1 (hide)

cpe:2.3:a:thepluginpeople:enterprise_mail_handler:*:*:*:*:*:jira:*:*

History

03 Apr 2025, 16:43

Type Values Removed Values Added
First Time Thepluginpeople
Thepluginpeople enterprise Mail Handler
References () https://github.com/florkie/CVE/blob/main/CVE-2025-25363.md - () https://github.com/florkie/CVE/blob/main/CVE-2025-25363.md - Third Party Advisory
References () https://marketplace.atlassian.com/apps/4832/enterprise-mail-handler-for-jira-jemh/version-history?versionHistoryHosting=dataCenter - () https://marketplace.atlassian.com/apps/4832/enterprise-mail-handler-for-jira-jemh/version-history?versionHistoryHosting=dataCenter - Release Notes
CPE cpe:2.3:a:thepluginpeople:enterprise_mail_handler:*:*:*:*:*:jira:*:*

19 Mar 2025, 19:15

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de Cross Site Scripting (XSS) almacenado y autenticadas en The Plugin People Enterprise Mail Handler for Jira Data Center (JEMH) anterior a v4.1.69-dc permite a atacantes con privilegios de administrador ejecutar Javascript arbitrario en el contexto del navegador de un usuario mediante la inyección de un payload manipulado en el campo HTML de una plantilla.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-80

13 Mar 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-13 18:15

Updated : 2025-04-03 16:43


NVD link : CVE-2025-25363

Mitre link : CVE-2025-25363

CVE.ORG link : CVE-2025-25363


JSON object : View

Products Affected

thepluginpeople

  • enterprise_mail_handler
CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)