Описание
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, a reflected HTML injection vulnerability exists in the Projects module where the filter URL parameter is rendered into the DOM without output encoding when the user clicks "Filter." While <script> and <iframe> are blocked, <svg>, <a>, and formatting tags (<h1>, <b>, <u>) render without restriction — enabling SVG-based phishing buttons, external redirect links, and content spoofing within the trusted application origin. Version 2.0.0 fixes this issue.
Ссылки
- ExploitVendor Advisory
- Release Notes
Уязвимые конфигурации
Конфигурация 1Версия до 2.0.0 (исключая)
cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*
EPSS
Процентиль: 13%
0.00221
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
github
7 месяцев назад
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module
EPSS
Процентиль: 13%
0.00221
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79