Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jf6p-4hgv-v6qh

Опубликовано: 28 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Duplicate Advisory: Leantime affected by Improper Neutralization of HTML Tags

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-95j3-435g-vjcp. This link is maintained to preserve external references.

Original Description

Cross Site Scripting vulnerability in Leantime v3.2.1 and before allows an authenticated attacker to execute arbitrary code and obtain sensitive information via the first name field in processMentions().

Пакеты

Наименование

leantime/leantime

composer
Затронутые версииВерсия исправления

< 3.3

3.3

6.5 Medium

CVSS3

Дефекты

CWE-80

6.5 Medium

CVSS3

Дефекты

CWE-80