PT-2026-22222 · Unknown · Initiative

G3Xar

·

Publicado

2026-02-26

·

Atualizado

2026-03-03

·

CVE-2026-28274

CVSS v3.1

8.7

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Initiative versions prior to 0.32.4
Description Initiative is a self-hosted project management platform vulnerable to Stored Cross-Site Scripting (XSS) in the document upload functionality. Users with upload permissions within the "Initiatives" section can upload malicious .html or .htm files. These files are served under the application’s origin without proper sandboxing, allowing embedded JavaScript to execute in the application’s context. This can lead to the exfiltration of authentication tokens, session cookies, or other sensitive data to an attacker-controlled server. Sharing the direct file link may also result in the execution of the malicious script when accessed.
Recommendations Upgrade to version 0.32.4 or later.

Exploit

Correção

Unrestricted File Upload

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-28274
GHSA-V38C-X27X-P584

Produtos afetados

Initiative