PT-2021-4536 · Redmine · Redmine

Maik Stegemann

·

Published

2021-04-06

·

Updated

2024-03-06

·

CVE-2020-36307

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Redmine versions 4.0.0 through 4.0.6 Redmine versions 4.1.0 through 4.1.0
Description The issue is related to stored XSS via textile inline links, which can be exploited by a remote attacker to impact data integrity. The vulnerability is due to the lack of protection measures for the web page structure.
Recommendations For Redmine versions 4.0.0 through 4.0.6, update to version 4.0.7 or later. For Redmine versions 4.1.0 through 4.1.0, update to version 4.1.1 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2021-05196
BIT-REDMINE-2020-36307
CVE-2020-36307
DLA-2658-1

Affected Products

Redmine