Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in "Reaction to comment" feature.
References
| Link | Resource |
|---|---|
| https://github.com/wekan/wekan/blob/master/CHANGELOG.md | Release Notes |
| https://github.com/wekan/wekan/commit/47ac33d6c234359c31d9b5eae49ed3e793907279 | Patch |
Configurations
History
No history.
Information
Published : 2023-05-22 13:15
Updated : 2023-05-31 13:38
NVD link : CVE-2023-31779
Mitre link : CVE-2023-31779
CVE.ORG link : CVE-2023-31779
JSON object : View
Products Affected
wekan_project
- wekan
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
