PT-2025-52828 · Unknown · Orangescrum

Hubert Wojciechowski

·

Published

2025-12-23

·

Updated

2025-12-23

·

CVE-2021-47716

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Orangescrum version 1.8.0
Description The application has multiple cross-site scripting issues that permit authenticated attackers to inject malicious scripts through various input parameters. Attackers can exploit parameters such as projid, CS message, and name to execute arbitrary JavaScript code in victim’s browsers by submitting crafted payloads through application endpoints.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-47716

Affected Products

Orangescrum