Unknown · Plugin People Enterprise Mail Handler · CVE-2025-25363
Name of the Vulnerable Software and Affected Versions:
The Plugin People Enterprise Mail Handler for Jira Data Center versions prior to 4.1.69-dc
Description:
An authenticated stored cross-site scripting issue allows attackers with Administrator privileges to execute arbitrary Javascript in the context of a user's browser by injecting a crafted payload into the HTML field of a template.
Recommendations:
For versions prior to 4.1.69-dc, update to version 4.1.69-dc or later to resolve the issue. As a temporary workaround, consider restricting access to the template HTML field to minimize the risk of exploitation.