Описание
Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the application settings section. The fields application_language, application_date_format,application_timezone and application_time_format allow arbirary user input which is reflected. The vulnerability can become xss if the user input is javascript code that bypass CSP. This vulnerability is fixed in 1.2.41.
Ссылки
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:kanboard:kanboard:1.2.40:*:*:*:*:*:*:*
EPSS
Процентиль: 31%
0.00382
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-80
CWE-79
Связанные уязвимости
CVSS3: 5.5
debian
почти 2 года назад
Kanboard is project management software that focuses on the Kanban met ...
EPSS
Процентиль: 31%
0.00382
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-80
CWE-79