CVE-2023-47260: XSS
Published Nov 5, 2023
·Updated
Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.
Affected Software
2 affected components
Redmine Redmine<4.2.11
Redmine Redmine>=5.0.0<5.0.6
Event History
Nov 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Redmine vulnerability?
The vulnerability ID for this Redmine vulnerability is CVE-2023-47260.
2
What is the title of this Redmine vulnerability?
The title of this Redmine vulnerability is Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.
3
What is the severity of CVE-2023-47260?
The severity of CVE-2023-47260 is medium with a severity value of 6.1.
4
How does Redmine before 4.2.11 and 5.0.x before 5.0.6 allow XSS?
Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS through thumbnails.
5
How can I fix this vulnerability in Redmine?
To fix this vulnerability in Redmine, you need to update to version 4.2.11 if you are using a version before that, or update to version 5.0.6 if you are using a version between 5.0.0 and 5.0.6.