•  
      request #33656 XSS on the success message of a kanban deletion
    Infos
    #33656
    Thomas Gerbet (tgerbet)
    2023-08-21 08:45
    2023-08-07 10:08
    35253
    Details
    XSS on the success message of a kanban deletion

    The label of a kanban is not properly escaped when displaying the success message of the kanban deletion.

    Impact

    An agile dashboard administrator deleting a kanban with a malicious label can be forced to execute uncontrolled code.
    CVSSv3.1 score: 4.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N)

    Exploitation

    1. Have a kanban named something like this <img src=a onerror=alert(1)>
    2. Delete it

    References

    CWE 79
    OWASP Cross-site Scripting
    CVE-2023-39521

    Agile Dashboard
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2023-08-07
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2023-08-09 08:37

    CVE-2023-39521 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2023-08-07 10:54
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes