The WorklogPRO - Jira Timesheets plugin in the Jira Data Center before 4.24.2-jira9, 4.24.2-jira10 and 4.24.2-jira11 allows attackers to inject arbitrary HTML or JavaScript via XSS. This is exploited via a crafted payload placed in the name of a filter. This code is executed in the browser when the user attempts to create a timesheet with the filter timesheet type on the custom timesheet dialog because the filter name is not properly sanitized during the action.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-20 16:16
Updated : 2026-01-26 15:05
NVD link : CVE-2025-67824
Mitre link : CVE-2025-67824
CVE.ORG link : CVE-2025-67824
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
