๐Ÿ” CVE Alert

CVE-2023-28485

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated users to inject arbitrary web script or HTML via names of file attachments. Any user can obtain the privilege to rename within their own board (where they have BoardAdmin access), and renameAttachment does not block XSS payloads.

Vendor n/a
Product n/a
Published Jun 26, 2023
Last Updated Dec 4, 2024
Stay Ahead of the Next One

Get instant alerts for n/a n/a

Be the first to know when new unknown vulnerabilities affecting n/a n/a are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / n/a
n/a

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wekan.github.io: https://wekan.github.io/ wekan.github.io: https://wekan.github.io/hall-of-fame/filebleed/ packetstormsecurity.com: http://packetstormsecurity.com/files/172649/Wekan-6.74-Cross-Site-Scripting.html