CVE-2009-4459: XSS
Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary script via UTF-7 encoded values in the title parameter to a new issue page, which may be interpreted as script by Internet Explorer 7 and 8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4459?
CVE-2009-4459 is classified as a high-severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2009-4459?
To mitigate CVE-2009-4459, users should upgrade to a newer version of Redmine that addresses the XSS vulnerability.
Which versions of Redmine are affected by CVE-2009-4459?
CVE-2009-4459 impacts Redmine versions 0.8.7 and earlier, including several specific earlier versions.
What type of vulnerability is CVE-2009-4459?
CVE-2009-4459 is a cross-site scripting (XSS) vulnerability that enables attackers to inject arbitrary scripts.
What are the potential risks associated with CVE-2009-4459?
The risks of CVE-2009-4459 include unauthorized access to sensitive information and the execution of malicious scripts in the context of users' browsers.