Cross-Site Scripting Vulnerability in Redmine by Redmine
CVE-2023-47259

6.1MEDIUM

Key Information:

Vendor

Redmine

Status
Vendor
CVE Published:
5 November 2023

What is CVE-2023-47259?

A vulnerability has been identified in Redmine, affecting versions prior to 4.2.11 and 5.0.x prior to 5.0.6, where the Textile formatter is susceptible to Cross-Site Scripting (XSS) attacks. This flaw can allow an attacker to inject malicious scripts into web pages viewed by other users, compromising user sessions and data integrity. Maintaining updated software and applying the latest security patches is crucial to mitigate such vulnerabilities.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.