(:A cross-site scripting vulnerability has been identified in Atlassian JIRA..:A remote attacker could exploit it by inciting his victim to follow a specially crafted URL in order to execute arbitrary JavaScript/HTML code.::The vulnerability is due to insufficient validation of input user parameters in pages carrying attached files.::A proof of concept is available.)