The host is installed with Atlassian Jira Server before 8.5.5, 8.6.0 before 8.8.2, 8.9.0 before 8.9.1 and is prone to a cross site scripting vulnerability. A flaw is present in the application which fails to properly handle the issue attachments. Successful exploitation allow remote attackers to inject arbitrary HTML or JavaScript.