Improper HTML Sanitization in JetBrains YouTrack Leading to XSS Attacks
CVE-2024-50581
5.4MEDIUM
What is CVE-2024-50581?
In JetBrains YouTrack versions preceding 2024.3.47707, a flaw in HTML sanitization processes could permit an attacker to execute arbitrary scripts within a user's browser session through specially crafted comment tags. This vulnerability poses a risk to session hijacking and unauthorized actions, emphasizing the need for quick remediation and patching.