PT-2024-25858 · Microsoft+1 · Sharepoint 2019+1
Published
2024-06-25
·
Updated
2024-11-05
·
CVE-2024-34400
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
VirtoSoftware Virto Kanban Board Web Part versions prior to 5.3.5.1 for SharePoint 2019
Description
An issue was discovered in the software, specifically with the "/ layouts/15/Virto.KanbanTaskManager/api/KanbanData.ashx" API endpoint, where a LinkTitle2 XSS issue exists.
Recommendations
For versions prior to 5.3.5.1, update to version 5.3.5.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/ layouts/15/Virto.KanbanTaskManager/api/KanbanData.ashx" API endpoint to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sharepoint 2019
Virto Kanban Board Web Part