Описание
Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the application settings section. The fields application_language, application_date_format,application_timezone and application_time_format allow arbirary user input which is reflected. The vulnerability can become xss if the user input is javascript code that bypass CSP. This vulnerability is fixed in 1.2.41.
Ссылки
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:kanboard:kanboard:1.2.40:*:*:*:*:*:*:*
EPSS
Процентиль: 26%
0.00091
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-80
CWE-79
Связанные уязвимости
CVSS3: 5.5
debian
около 1 года назад
Kanboard is project management software that focuses on the Kanban met ...
EPSS
Процентиль: 26%
0.00091
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-80
CWE-79