PT-2023-29433 · Unknown · Change Request
Michitux
·
Published
2023-10-12
·
Updated
2023-10-18
·
CVE-2023-45138
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Change Request versions 0.11 through 1.9.2
Description
The issue allows a user without specific rights to perform script injection and remote code execution by inserting an appropriate title when creating a new Change Request. This is particularly critical as Change Request is intended for use by users without particular rights.
Recommendations
For versions prior to 1.9.2, upgrade to Change Request 1.9.2 to resolve the issue.
As a temporary workaround for versions prior to 1.9.2, edit the document
ChangeRequest.Code.ChangeRequestSheet and perform the same change as in the fix commit.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Change Request