PT-2024-25858 · Microsoft+1 · Sharepoint 2019+1

Published

2024-06-25

·

Updated

2024-11-05

·

CVE-2024-34400

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions VirtoSoftware Virto Kanban Board Web Part versions prior to 5.3.5.1 for SharePoint 2019
Description An issue was discovered in the software, specifically with the "/ layouts/15/Virto.KanbanTaskManager/api/KanbanData.ashx" API endpoint, where a LinkTitle2 XSS issue exists.
Recommendations For versions prior to 5.3.5.1, update to version 5.3.5.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/ layouts/15/Virto.KanbanTaskManager/api/KanbanData.ashx" API endpoint to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2024-34400

Affected Products

Sharepoint 2019
Virto Kanban Board Web Part