CVE-2023-28485
A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated users to inject arbitrary web script or HTML via names of file attachments.
Does this matter?
Lower severity and a low EPSS score (0.97%). Track it; it rarely justifies an emergency change on its own.
Description
A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated users to inject arbitrary web script or HTML via names of file attachments. Any user can obtain the privilege to rename within their own board (where they have BoardAdmin access), and renameAttachment does not block XSS payloads.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- wekan project/wekan
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/172649/Wekan-6.74-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://wekan.github.io/Product
- https://wekan.github.io/hall-of-fame/filebleed/Exploit, Vendor Advisory
- http://packetstormsecurity.com/files/172649/Wekan-6.74-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://wekan.github.io/Product
- https://wekan.github.io/hall-of-fame/filebleed/Exploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.