PT-2025-52828 · Unknown · Orangescrum
Hubert Wojciechowski
·
Published
2025-12-23
·
Updated
2025-12-23
·
CVE-2021-47716
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Orangescrum version 1.8.0
Description
The application has multiple cross-site scripting issues that permit authenticated attackers to inject malicious scripts through various input parameters. Attackers can exploit parameters such as
projid, CS message, and name to execute arbitrary JavaScript code in victim’s browsers by submitting crafted payloads through application endpoints.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Orangescrum