CVE-2012-0327: XSS
Cross-site scripting (XSS) vulnerability in Redmine before 1.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0327?
CVE-2012-0327 has a medium severity level due to its potential to allow remote attackers to perform cross-site scripting (XSS) attacks.
How do I fix CVE-2012-0327?
To fix CVE-2012-0327, upgrade Redmine to version 1.3.2 or later, which addresses the vulnerability.
Which versions of Redmine are affected by CVE-2012-0327?
CVE-2012-0327 affects all versions of Redmine prior to 1.3.2, including versions 0.1.0 through 1.3.1.
What type of vulnerability is CVE-2012-0327?
CVE-2012-0327 is a cross-site scripting (XSS) vulnerability that allows for the injection of arbitrary web scripts or HTML.
Can CVE-2012-0327 impact user data?
Yes, if exploited, CVE-2012-0327 can potentially compromise user data by allowing attackers to execute malicious scripts in the context of the user's session.