Cross Site Scripting in Redmine Custom Query Handler
CVE-2025-4011
5.1MEDIUM
What is CVE-2025-4011?
A Cross Site Scripting vulnerability has been identified within the Custom Query Handler component of Redmine versions 6.0.0 through 6.0.3. This flaw permits attackers to manipulate the input argument 'Name', potentially allowing them to execute malicious scripts remotely. It is imperative for users to upgrade to version 6.0.4 or later to protect against this security risk and ensure the integrity of their applications.
Affected Version(s)
Redmine 6.0.0
Redmine 6.0.1
Redmine 6.0.2
