CVE-2020-36306: XSS
Published Apr 6, 2021
·Updated
Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the backurl field.
Affected Software
3 affected components
Redmine Redmine<4.0.7
Redmine Redmine>=4.1.0<4.1.1
Debian Debian Linux=9.0
Event History
Apr 6, 2021
CVE Published
via MITRE·07:59 AM
Data Sourced
via MITRE·07:59 AM
Description
Frequently Asked Questions
1
What is CVE-2020-36306?
CVE-2020-36306 is a vulnerability in Redmine before 4.0.7 and 4.1.x before 4.1.1 that allows for cross-site scripting (XSS) attacks via the back_url field.
2
How severe is CVE-2020-36306?
CVE-2020-36306 has a severity level of medium with a CVSS score of 6.1.
3
What is the affected software?
The affected software includes Redmine versions up to and excluding 4.0.7, Redmine versions between 4.1.0 and 4.1.1, and Debian Linux version 9.0.
4
How can I fix CVE-2020-36306?
To fix CVE-2020-36306, it is recommended to upgrade your Redmine installation to version 4.0.7 or later.
5
Where can I find more information about CVE-2020-36306?
You can find more information about CVE-2020-36306 in the Debian LTS Announcement and the Redmine Security Advisories.