Cross Site Scripting in Redmine Custom Query Handler
CVE-2025-4011

5.1MEDIUM

Key Information:

Vendor

Redmine

Status
Vendor
CVE Published:
28 April 2025

What is CVE-2025-4011?

A Cross Site Scripting vulnerability has been identified within the Custom Query Handler component of Redmine versions 6.0.0 through 6.0.3. This flaw permits attackers to manipulate the input argument 'Name', potentially allowing them to execute malicious scripts remotely. It is imperative for users to upgrade to version 6.0.4 or later to protect against this security risk and ensure the integrity of their applications.

Affected Version(s)

Redmine 6.0.0

Redmine 6.0.1

Redmine 6.0.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hauvcp (VulDB User)
.