PT-2023-9189 · Redmine · Redmine

Published

2023-11-05

·

Updated

2024-05-24

·

CVE-2023-47260

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Redmine versions prior to 4.2.11 Redmine versions 5.0.x prior to 5.0.6
Description The issue is related to a lack of protection for the web page structure in the Thumbnails component of the Redmine web application, allowing for cross-site scripting (XSS) attacks. This could enable a remote attacker to conduct inter-site script attacks.
Recommendations For Redmine versions prior to 4.2.11, update to version 4.2.11 or later. For Redmine versions 5.0.x prior to 5.0.6, update to version 5.0.6 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-04495
BIT-REDMINE-2023-47260
CVE-2023-47260
DSA-5699-1

Affected Products

Redmine