Описание
Leantime affected by Improper Neutralization of HTML Tags
Summary
HTML can be arbitrarily injected into emails from Leantime due to improper neutralization of HTML tags in users' first names. This effectively allows for the creation of phishing emails from a Leantime instance's email address.
Ссылки
- https://github.com/Leantime/leantime/security/advisories/GHSA-95j3-435g-vjcp
- https://nvd.nist.gov/vuln/detail/CVE-2025-28254
- https://github.com/Leantime/leantime/commit/ce1d2073e4601183e1bdd90f4b433d16aee46a50
- https://github.com/Leantime/leantime/blob/0e7ddbbe3d582f657a1dddfef7b3419ae588cbf7/app/Domain/Notifications/Services/Notifications.php#L128
Пакеты
Наименование
leantime/leantime
composer
Затронутые версииВерсия исправления
< 3.3
3.3
Связанные уязвимости
CVSS3: 5.4
nvd
11 месяцев назад
Cross Site Scripting vulnerability in Leantime v3.2.1 and before allows an authenticated attacker to execute arbitrary code and obtain sensitive information via the first name field in processMentions().