Stored Cross-Site Scripting in ZenTao by Easysoft
CVE-2023-46475
5.4MEDIUM
What is CVE-2023-46475?
A Stored Cross-Site Scripting (XSS) vulnerability has been identified in ZenTao 18.3, allowing attackers to inject malicious JavaScript code through the project name field. When a user creates a new project, they can potentially execute harmful scripts that compromise the security of other users interacting with the application. This vulnerability poses significant risks, as it can lead to session hijacking, unauthorized actions, and exposure of sensitive data.
