The host is installed with Atlassian Jira Server before 8.5.14, 8.6.0 before 8.13.6, or 8.14.0 before 8.16.1 and is prone to a cross-site scripting vulnerability. A flaw is present in the application which fails to properly handle the Export HTML Report feature. Successful exploitation could allow remote attackers to inject arbitrary html or javascript.