ZeroHour

CVE-2023-31779

CVSS 3.1
5.4 medium
EPSS
<1%p45
Published
()
Modified
Description

Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in "Reaction to comment" feature.

Vendors
wekan project
Products
wekan
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.