PT-2025-18051 · Redmine · Redmine

·

CVE-2025-4011

·

Published

2025-04-28

·

Updated

2025-04-28

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Redmine versions 6.0.0 through 6.0.3
Description A vulnerability has been found in the Custom Query Handler component, affecting unknown code. The manipulation of the Name argument leads to cross-site scripting. The attack can be initiated remotely.
Recommendations For versions 6.0.0 through 6.0.3, upgrade to version 6.0.4 to address this issue. As a temporary workaround, consider restricting the manipulation of the Name argument in the Custom Query Handler component until the upgrade is applied.

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-4011

Affected Products

Redmine