The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThreshold parameter.
| Software | From | Fixed in |
|---|---|---|
| atlassian / jira | 6.2.1 | 7.4.4 |