First published: Mon Mar 29 2021(Updated: )
Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Redmine Redmine | >=4.1.0<4.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29274 is a vulnerability in Redmine 4.1.x before 4.1.2 that allows XSS (Cross-Site Scripting) attacks.
CVE-2021-29274 affects Redmine versions 4.1.x before 4.1.2.
The severity of CVE-2021-29274 is medium with a CVSS score of 6.1.
CVE-2021-29274 can be exploited by injecting malicious scripts into an issue's subject field in Redmine, which can then be executed by other users.
To fix CVE-2021-29274, it is recommended to upgrade Redmine to version 4.1.2 or later.