PT-2023-23960 · Kanboard · Kanboard

Ry0Tak

·

Published

2023-05-30

·

Updated

2023-06-07

·

CVE-2023-32685

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kanboard versions prior to 1.2.29
Description The issue arises from improper handling of elements under the contentEditable element, allowing maliciously crafted clipboard content to inject arbitrary HTML tags into the DOM. A low-privileged attacker can exploit this by tricking the victim into pasting malicious screenshot data, potentially achieving cross-site scripting if Content Security Policy (CSP) is improperly configured.
Recommendations For versions prior to 1.2.29, update to version 1.2.29 to resolve the issue. As a temporary workaround, consider restricting the ability to attach documents and pasting screenshot data to minimize the risk of exploitation. Additionally, ensure that Content Security Policy (CSP) is properly configured to reduce the risk of cross-site scripting.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-32685
GHSA-HJMW-GM82-R4GV

Affected Products

Kanboard