PT-2024-36008 · Kanboard+1 · Kanboard+1

Mariotesoro

·

Published

2024-12-05

·

Updated

2024-12-06

·

CVE-2024-54001

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Kanboard versions prior to 1.2.41
Description: Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the application settings section. The fields application language, application date format, application timezone, and application time format allow arbitrary user input which is reflected. This issue can become a cross-site scripting (XSS) vulnerability if the user input is JavaScript code that bypasses Content Security Policy (CSP).
Recommendations: For versions prior to 1.2.41, update to version 1.2.41 to resolve the issue. As a temporary workaround, consider restricting user input in the application language, application date format, application timezone, and application time format fields to prevent arbitrary HTML injection.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-54001
GHSA-4VVP-JF72-CHRJ

Affected Products

Debian
Kanboard