Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9hv3-wvf3-ffmp

Опубликовано: 15 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can be served with attacker-controlled Content-Type (text/html), allowing execution of attacker-supplied HTML/JS in the application's origin and enabling session/token theft and CSRF actions.

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can be served with attacker-controlled Content-Type (text/html), allowing execution of attacker-supplied HTML/JS in the application's origin and enabling session/token theft and CSRF actions.

EPSS

Процентиль: 14%
0.00046
Низкий

8.1 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.1
nvd
около 2 месяцев назад

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can be served with attacker-controlled Content-Type (text/html), allowing execution of attacker-supplied HTML/JS in the application's origin and enabling session/token theft and CSRF actions.

EPSS

Процентиль: 14%
0.00046
Низкий

8.1 High

CVSS3

Дефекты

CWE-79