CVE-2019-17092

An XSS vulnerability in project list in OpenProject before 9.0.4 and 10.x before 10.0.2 allows remote attackers to inject arbitrary web script or HTML via the sortBy parameter because error messages are mishandled.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*
cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:31

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/154851/OpenProject-10.0.1-9.0.3-Cross-Site-Scripting.html - () http://packetstormsecurity.com/files/154851/OpenProject-10.0.1-9.0.3-Cross-Site-Scripting.html -
References () http://seclists.org/fulldisclosure/2019/Oct/29 - () http://seclists.org/fulldisclosure/2019/Oct/29 -
References () https://groups.google.com/forum/#%21topic/openproject-security/tEsx0UXWxXA - () https://groups.google.com/forum/#%21topic/openproject-security/tEsx0UXWxXA -
References () https://seclists.org/bugtraq/2019/Oct/19 - () https://seclists.org/bugtraq/2019/Oct/19 -
References () https://www.openproject.org/release-notes/openproject-10-0-2/ - Release Notes, Vendor Advisory () https://www.openproject.org/release-notes/openproject-10-0-2/ - Release Notes, Vendor Advisory
References () https://www.openproject.org/release-notes/openproject-9-0-4/ - Release Notes, Vendor Advisory () https://www.openproject.org/release-notes/openproject-9-0-4/ - Release Notes, Vendor Advisory

07 Nov 2023, 03:06

Type Values Removed Values Added
References
  • {'url': 'https://groups.google.com/forum/#!topic/openproject-security/tEsx0UXWxXA', 'name': 'https://groups.google.com/forum/#!topic/openproject-security/tEsx0UXWxXA', 'tags': ['Patch', 'Third Party Advisory'], 'refsource': 'MISC'}
  • () https://groups.google.com/forum/#%21topic/openproject-security/tEsx0UXWxXA -

Information

Published : 2019-10-09 19:15

Updated : 2024-11-21 04:31


NVD link : CVE-2019-17092

Mitre link : CVE-2019-17092

CVE.ORG link : CVE-2019-17092


JSON object : View

Products Affected

openproject

  • openproject
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')