CVE-2008-4481: XSS
Published Oct 8, 2008
·Updated
Cross-site scripting (XSS) vulnerability in Redmine 0.7.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
18 affected components
Redmine Redmine=0.6.0
Redmine Redmine=0.4.1
Redmine Redmine=0.7.0-rc1
Redmine Redmine=0.7.0
Redmine Redmine=0.2.2
Redmine Redmine=0.6.3
Redmine Redmine=0.5.0
Redmine Redmine=0.6.1
Redmine Redmine<=0.7.2
Redmine Redmine=0.7.1
Redmine Redmine=0.6.2
Redmine Redmine=0.4.0
Redmine Redmine=0.1.0
Redmine Redmine=0.6.4
Redmine Redmine=0.4.2
Redmine Redmine=0.2.1
Redmine Redmine=0.5.1
Redmine Redmine=0.3.0
Remediation
Patch Available
Event History
Oct 8, 2008
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4481?
CVE-2008-4481 is classified as a high-severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2008-4481?
To fix CVE-2008-4481, it is recommended to upgrade to Redmine version 0.7.3 or later.
3
Who is affected by CVE-2008-4481?
CVE-2008-4481 affects multiple versions of Redmine up to and including 0.7.2.
4
What are the implications of CVE-2008-4481?
The implications of CVE-2008-4481 include the possibility for remote attackers to inject arbitrary web scripts or HTML.
5
Is CVE-2008-4481 easy to exploit?
Yes, CVE-2008-4481 is typically considered easy to exploit due to its nature as an XSS vulnerability.