Jenkins Favorite Plugin version 2.2.0 and older is vulnerable to CSRF resulting in data modification
CVSS Metrics