ZeroHour

CVE-2017-15574

CVSS 3.0
6.1 medium
EPSS
1%p65
Published
()
Modified
Description

In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.

Vendors
redminedebian
Products
redmine, debian linux
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.