PT-2025-6068 · Unknown · Openproject
Meanknt
·
Published
2025-02-10
·
Updated
2025-08-27
·
CVE-2025-24892
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenProject versions prior to 15.2.1
Description
The issue arises from the application's failure to properly sanitize user input before displaying it in the Group Management section. Specifically, groups created with HTML script tags are not properly escaped before rendering them in a project.
Recommendations
For versions prior to 15.2.1, update to OpenProject version 15.2.1 to resolve the issue.
As a temporary workaround for those unable to upgrade, apply the patch manually.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openproject