- 
    Bug 
- 
    Resolution: Fixed
- 
    Medium 
- 
    6.2.1, 7.4.2
- 
        6.02
- 
        Severity 2 - Major
- 
        
The IncomingMailServers resource in Atlassian JIRA from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThreshold parameter .
- is related to
- 
                    JRASERVER-67526 XSS in IncomingMailServer resource - CVE-2018-13387 -         
- Closed
 
-