CVE-2025-57681: XSS
The WorklogPRO - Timesheets for Jira plugin in Jira Data Center before version 4.23.6-jira10 and before version 4.23.5-jira9 allows users and attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability. The vulnerability is exploited via a specially crafted payload placed in an issue's summary field
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57681?
CVE-2025-57681 has been classified with a high severity due to its potential for exploitation through Cross-Site Scripting (XSS).
How do I fix CVE-2025-57681?
To fix CVE-2025-57681, update the WorklogPRO - Timesheets for Jira plugin to version 4.23.6-jira10 or 4.23.5-jira9 or newer.
Who is affected by CVE-2025-57681?
CVE-2025-57681 affects users of the WorklogPRO - Timesheets for Jira plugin in Jira Data Center versions prior to 4.23.6-jira10 and 4.23.5-jira9.
What type of vulnerability is CVE-2025-57681?
CVE-2025-57681 is a Cross-Site Scripting (XSS) vulnerability that allows the injection of arbitrary HTML or JavaScript.
What can attackers do with CVE-2025-57681?
Attackers can exploit CVE-2025-57681 to inject malicious scripts that could compromise user sessions or perform unwanted actions in the context of the user.