First published: Sun Nov 05 2023(Updated: )
Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
<4.2.11 | ||
>=5.0.0<5.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Redmine vulnerability is CVE-2023-47260.
The title of this Redmine vulnerability is Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.
The severity of CVE-2023-47260 is medium with a severity value of 6.1.
Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS through thumbnails.
To fix this vulnerability in Redmine, you need to update to version 4.2.11 if you are using a version before that, or update to version 5.0.6 if you are using a version between 5.0.0 and 5.0.6.