PT-2023-9189 · Redmine · Redmine

CVE-2023-47260

·

Publicado

2023-11-05

·

Atualizado

2024-05-24

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Redmine versions prior to 4.2.11 Redmine versions 5.0.x prior to 5.0.6
Description The issue is related to a lack of protection for the web page structure in the Thumbnails component of the Redmine web application, allowing for cross-site scripting (XSS) attacks. This could enable a remote attacker to conduct inter-site script attacks.
Recommendations For Redmine versions prior to 4.2.11, update to version 4.2.11 or later. For Redmine versions 5.0.x prior to 5.0.6, update to version 5.0.6 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-04495
BIT-REDMINE-2023-47260
CVE-2023-47260
DSA-5699-1

Produtos afetados

Redmine