First published: Sun Nov 05 2023(Updated: )
Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
<4.2.11 | ||
>=5.0.0<5.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-47258.
The severity of CVE-2023-47258 is medium with a CVSS score of 6.1.
CVE-2023-47258 affects Redmine versions before 4.2.11 and 5.0.x before 5.0.6.
CVE-2023-47258 allows XSS (Cross-Site Scripting) attacks in a Markdown formatter in Redmine.
To fix CVE-2023-47258, upgrade Redmine to version 4.2.11 or 5.0.6 or later.