PT-2024-36008 · Kanboard+1 · Kanboard+1
Mariotesoro
·
Published
2024-12-05
·
Updated
2024-12-06
·
CVE-2024-54001
CVSS v3.1
5.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Kanboard versions prior to 1.2.41
Description:
Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the application settings section. The fields
application language, application date format, application timezone, and application time format allow arbitrary user input which is reflected. This issue can become a cross-site scripting (XSS) vulnerability if the user input is JavaScript code that bypasses Content Security Policy (CSP).Recommendations:
For versions prior to 1.2.41, update to version 1.2.41 to resolve the issue. As a temporary workaround, consider restricting user input in the
application language, application date format, application timezone, and application time format fields to prevent arbitrary HTML injection.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Kanboard