CVE-2023-28485: XSS
A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated users to inject arbitrary web script or HTML via names of file attachments. Any user can obtain the privilege to rename within their own board (where they have BoardAdmin access), and renameAttachment does not block XSS payloads.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-28485?
CVE-2023-28485 is a stored cross-site scripting (Stored XSS) vulnerability in the file preview feature of WeKan before version 6.75.
What is the severity of CVE-2023-28485?
CVE-2023-28485 has a severity rating of 5.4, which is considered medium.
How does CVE-2023-28485 affect WeKan?
CVE-2023-28485 allows remote authenticated users to inject arbitrary web script or HTML via names of file attachments in WeKan versions prior to 6.75.
Can any user exploit CVE-2023-28485?
Any user with BoardAdmin access in their own board can exploit CVE-2023-28485 within WeKan versions prior to 6.75.
Are there any references related to CVE-2023-28485?
Yes, you can find more information about CVE-2023-28485 at the following links: [Packet Storm Security](http://packetstormsecurity.com/files/172649/Wekan-6.74-Cross-Site-Scripting.html) and the [Wekan official website](https://wekan.github.io/).