CVE-2023-33961: XSS
Leantime is a lean open source project management system. Starting in version 2.3.21, an authenticated user with commenting privileges can inject malicious Javascript into a comment. Once the malicious comment is loaded in the browser by a user, the malicious Javascript code executes. As of time of publication, a patch does not exist.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-33961?
CVE-2023-33961 is a vulnerability in the Leantime project management system, starting from version 2.3.21.
What is the severity of CVE-2023-33961?
The severity of CVE-2023-33961 is high, with a severity value of 5.4.
How can an attacker exploit CVE-2023-33961?
An attacker with commenting privileges can exploit CVE-2023-33961 by injecting malicious JavaScript into a comment, which executes when loaded by a user's browser.
How can I fix the CVE-2023-33961 vulnerability?
To fix the CVE-2023-33961 vulnerability, update your Leantime installation to a version higher than 2.3.21.
Where can I find more information about CVE-2023-33961?
More information about CVE-2023-33961 can be found at the following link: [GitHub Advisory](https://github.com/Leantime/leantime/security/advisories/GHSA-359m-fp6q-65r7)