PT-2023-23960 · Kanboard · Kanboard
Ry0Tak
·
Published
2023-05-30
·
Updated
2023-06-07
·
CVE-2023-32685
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Kanboard versions prior to 1.2.29
Description
The issue arises from improper handling of elements under the
contentEditable element, allowing maliciously crafted clipboard content to inject arbitrary HTML tags into the DOM. A low-privileged attacker can exploit this by tricking the victim into pasting malicious screenshot data, potentially achieving cross-site scripting if Content Security Policy (CSP) is improperly configured.Recommendations
For versions prior to 1.2.29, update to version 1.2.29 to resolve the issue. As a temporary workaround, consider restricting the ability to attach documents and pasting screenshot data to minimize the risk of exploitation. Additionally, ensure that Content Security Policy (CSP) is properly configured to reduce the risk of cross-site scripting.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kanboard