← volver
CVE-2024-54001

Kanboard allows a persistent HTML injection site scripting in settings page date format

CVSS 5.5 MEDIUMEPSS 0.4%CWE-80
Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the application settings section. The fields application_language, application_date_format,application_timezone and application_time_format allow arbirary user input which is reflected. The vulnerability can become xss if the user input is javascript code that bypass CSP. This vulnerability is fixed in 1.2.41.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Productos afectados
kanboard · kanboard

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →