CVE-2024-27703: XSS
Published Mar 13, 2024
·Updated
Cross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do title parameter.
Affected Software
2 affected components
Leantime Leantime
Leantime Leantime=3.0.6
Event History
Mar 13, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27703?
CVE-2024-27703 is classified as a high severity Cross Site Scripting vulnerability.
2
How do I fix CVE-2024-27703?
To fix CVE-2024-27703, you should update Leantime to version 3.0.7 or later, which includes a patch for the vulnerability.
3
What are the potential impacts of CVE-2024-27703?
The potential impacts of CVE-2024-27703 include the ability for an attacker to execute arbitrary code on the victim's browser.
4
Who is affected by CVE-2024-27703?
CVE-2024-27703 affects all users of Leantime version 3.0.6, as this is where the vulnerability is present.
5
What attack vectors are associated with CVE-2024-27703?
CVE-2024-27703 can be exploited through a crafted request that includes malicious code in the to-do title parameter.