CVE-2019-19679: Xpand-It Xray Test Mangaement

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the Pre-Condition Summary entry point via the summary field of a Create Pre-Condition action for a new Test Issue.

Affected products

  • Xpand-It Xray Test Mangaement: before 3.5.5 (fixed in 3.5.5)

Published 2019-12-09. Last modified 2026-06-17.