PT-2026-22222 · Unknown · Initiative
G3Xar
·
Publicado
2026-02-26
·
Atualizado
2026-03-03
·
CVE-2026-28274
CVSS v3.1
8.7
Alta
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Initiative versions prior to 0.32.4
Description
Initiative is a self-hosted project management platform vulnerable to Stored Cross-Site Scripting (XSS) in the document upload functionality. Users with upload permissions within the "Initiatives" section can upload malicious
.html or .htm files. These files are served under the application’s origin without proper sandboxing, allowing embedded JavaScript to execute in the application’s context. This can lead to the exfiltration of authentication tokens, session cookies, or other sensitive data to an attacker-controlled server. Sharing the direct file link may also result in the execution of the malicious script when accessed.Recommendations
Upgrade to version 0.32.4 or later.
Exploit
Correção
Unrestricted File Upload
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Initiative