Redmine · Redmine · CVE-2009-4078
**Name of the Vulnerable Software and Affected Versions**
Redmine versions 0.8.5 and earlier
**Description**
The issue allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, which can lead to multiple cross-site scripting (XSS) vulnerabilities.
**Recommendations**
For Redmine versions 0.8.5 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.