CVE-2025-28254
- EPSS 0.21%
- Veröffentlicht 28.03.2025 00:00:00
- Zuletzt bearbeitet 07.04.2025 14:42:18
Cross Site Scripting vulnerability in Leantime v3.2.1 and before allows an authenticated attacker to execute arbitrary code and obtain sensitive information via the first name field in processMentions().
CVE-2024-27474
- EPSS 0.37%
- Veröffentlicht 10.04.2024 15:16:04
- Zuletzt bearbeitet 08.04.2025 15:22:10
Leantime 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF). This vulnerability allows malicious actors to perform unauthorized actions on behalf of authenticated users, specifically administrators.
CVE-2024-27476
- EPSS 0.21%
- Veröffentlicht 10.04.2024 15:16:04
- Zuletzt bearbeitet 08.04.2025 15:22:00
Leantime 3.0.6 is vulnerable to HTML Injection via /dashboard/show#/tickets/newTicket.
CVE-2024-27477
- EPSS 0.24%
- Veröffentlicht 10.04.2024 15:16:04
- Zuletzt bearbeitet 08.04.2025 15:21:48
In Leantime 3.0.6, a Cross-Site Scripting vulnerability exists within the ticket creation and modification functionality, allowing attackers to inject malicious JavaScript code into the title field of tickets (also known as to-dos). This stored XSS v...
CVE-2024-27705
- EPSS 0.11%
- Veröffentlicht 03.04.2024 22:15:06
- Zuletzt bearbeitet 08.04.2025 15:22:19
Cross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted PDF file to the files/browse endpoint.
CVE-2024-27703
- EPSS 0.43%
- Veröffentlicht 13.03.2024 22:15:11
- Zuletzt bearbeitet 08.04.2025 15:22:27
Cross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do title parameter.
CVE-2023-45826
- EPSS 16.2%
- Veröffentlicht 19.10.2023 19:15:16
- Zuletzt bearbeitet 21.11.2024 08:27:26
Leantime is an open source project management system. A 'userId' variable in `app/domain/files/repositories/class.files.php` is not parameterized. An authenticated attacker can send a carefully crafted POST request to `/api/jsonrpc` to exploit an SQL...
CVE-2023-33961
- EPSS 0.36%
- Veröffentlicht 30.05.2023 22:15:10
- Zuletzt bearbeitet 21.11.2024 08:06:17
Leantime is a lean open source project management system. Starting in version 2.3.21, an authenticated user with commenting privileges can inject malicious Javascript into a comment. Once the malicious comment is loaded in the browser by a user, the ...
CVE-2020-5292
- EPSS 0.29%
- Veröffentlicht 31.03.2020 19:15:14
- Zuletzt bearbeitet 21.11.2024 05:33:50
Leantime before versions 2.0.15 and 2.1-beta3 has a SQL Injection vulnerability. The impact is high. Malicious users/attackers can execute arbitrary SQL queries negatively affecting the confidentiality, integrity, and availability of the site. Attack...