PT-2023-9189 · Redmine · Redmine

CVE-2023-47260

·

Published

2023-11-05

·

Updated

2024-05-24

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Redmine versions prior to 4.2.11 Redmine versions 5.0.x prior to 5.0.6
Description The issue is related to a lack of protection for the web page structure in the Thumbnails component of the Redmine web application, allowing for cross-site scripting (XSS) attacks. This could enable a remote attacker to conduct inter-site script attacks.
Recommendations For Redmine versions prior to 4.2.11, update to version 4.2.11 or later. For Redmine versions 5.0.x prior to 5.0.6, update to version 5.0.6 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04495
BIT-REDMINE-2023-47260
CVE-2023-47260
DSA-5699-1

Affected Products

Redmine