Cross-Site Scripting Vulnerability in Redmine by Redmine
CVE-2023-47259
6.1MEDIUM
What is CVE-2023-47259?
A vulnerability has been identified in Redmine, affecting versions prior to 4.2.11 and 5.0.x prior to 5.0.6, where the Textile formatter is susceptible to Cross-Site Scripting (XSS) attacks. This flaw can allow an attacker to inject malicious scripts into web pages viewed by other users, compromising user sessions and data integrity. Maintaining updated software and applying the latest security patches is crucial to mitigate such vulnerabilities.
