HTML Injection in Kanboard's Group Management Feature by Kanboard
CVE-2024-22720
4.8MEDIUM
What is CVE-2024-22720?
Kanboard version 1.2.34 contains an HTML injection vulnerability in its group management feature. This flaw allows an attacker to insert arbitrary HTML code, potentially leading to malicious scripts being executed within the user’s browser context. If exploited, it could compromise user data and lead to further security breaches, emphasizing the need for timely security updates and user awareness.