CVE-2024-27477

In Leantime 3.0.6, a Cross-Site Scripting vulnerability exists within the ticket creation and modification functionality, allowing attackers to inject malicious JavaScript code into the title field of tickets (also known as to-dos). This stored XSS vulnerability can be exploited to perform Server-Side Request Forgery (SSRF) attacks.
Configurations

No configuration.

History

21 Nov 2024, 09:04

Type Values Removed Values Added
References
  • () https://www.vicarius.io/vsociety/posts/analyzing-leantime-xss-for-the-fun-time-diving-into-cve-2024-27477-for-a-beginner -
References () https://drive.proton.me/urls/35CKB8RV04#sEubCKVOuXqt - () https://drive.proton.me/urls/35CKB8RV04#sEubCKVOuXqt -
References () https://github.com/Leantime/leantime/blob/264a7dbc2c9b18f574821bf27dd568a287ee8498/app/Domain/Tickets/Controllers/ShowTicket.php#L20 - () https://github.com/Leantime/leantime/blob/264a7dbc2c9b18f574821bf27dd568a287ee8498/app/Domain/Tickets/Controllers/ShowTicket.php#L20 -
References () https://github.com/dead1nfluence/Leantime-POC/blob/main/README.md - () https://github.com/dead1nfluence/Leantime-POC/blob/main/README.md -

06 Nov 2024, 16:35

Type Values Removed Values Added
Summary
  • (es) En Leantime 3.0.6, existe una vulnerabilidad de Cross-Site Scripting dentro de la funcionalidad de creación y modificación de tickets, lo que permite a los atacantes inyectar código JavaScript malicioso en el campo de título de los tickets (también conocido como tareas pendientes). Esta vulnerabilidad XSS almacenada se puede aprovechar para realizar ataques de Server-Side Request Forgery (SSRF).
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

10 Apr 2024, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-10 15:16

Updated : 2024-11-21 09:04


NVD link : CVE-2024-27477

Mitre link : CVE-2024-27477

CVE.ORG link : CVE-2024-27477


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')