VulnerabilityModified
CVE-2023-31779
Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS).
MEDIUM 5.4EPSS 0.56%
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in "Reaction to comment" feature.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- wekan project/wekan
- Source
- cve@mitre.org
References
- https://github.com/wekan/wekan/blob/master/CHANGELOG.mdRelease Notes
- https://github.com/wekan/wekan/commit/47ac33d6c234359c31d9b5eae49ed3e793907279Patch
- https://github.com/wekan/wekan/blob/master/CHANGELOG.mdRelease Notes
- https://github.com/wekan/wekan/commit/47ac33d6c234359c31d9b5eae49ed3e793907279Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.