PT-2026-24739 · Git+2 · Openproject

Frozzipies

·

Publicado

2026-03-11

·

Atualizado

2026-03-15

·

CVE-2026-30235

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenProject versions prior to 17.2.0
Description OpenProject is an open-source, web-based project management software. A flaw exists due to improper validation of Markdown rendering, specifically in hyperlink handling. This allows an attacker to inject malicious hyperlink payloads that perform DOM clobbering. DOM clobbering can cause the entire page to crash or become blank by overwriting native DOM functions with HTML elements, leading to runtime errors during application initialization and halting further execution.
Recommendations Versions prior to 17.2.0 should be updated to version 17.2.0 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-30235
GHSA-9RV2-9XV5-GPQ8

Produtos afetados

Openproject