Openproject

Openproject

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.37%
  • Veröffentlicht 08.05.2023 21:15:11
  • Zuletzt bearbeitet 21.11.2024 08:01:28

OpenProject is open source project management software. Starting with version 7.4.0 and prior to version 12.5.4, when a user registers and confirms their first two-factor authentication (2FA) device for an account, existing logged in sessions for tha...

  • EPSS 0.3%
  • Veröffentlicht 14.12.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:29:53

OpenProject is a web-based project management software. OpenProject versions >= 12.0.0 are vulnerable to a SQL injection in the budgets module. For authenticated users with the "Edit budgets" permission, the request to reassign work packages to anoth...

  • EPSS 0.31%
  • Veröffentlicht 20.07.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:07:41

OpenProject is open-source, web-based project management software. In versions prior to 11.3.3, the `MessagesController` class of OpenProject has a `quote` method that implements the logic behind the Quote button in the discussion forums, and it uses...

  • EPSS 0.55%
  • Veröffentlicht 09.10.2019 19:15:13
  • Zuletzt bearbeitet 21.11.2024 04:31:40

An XSS vulnerability in project list in OpenProject before 9.0.4 and 10.x before 10.0.2 allows remote attackers to inject arbitrary web script or HTML via the sortBy parameter because error messages are mishandled.

Exploit
  • EPSS 80.49%
  • Veröffentlicht 13.05.2019 20:29:02
  • Zuletzt bearbeitet 21.11.2024 04:21:25

A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id parameter. The attack can be performed unauthenticated if OpenProject is configured not to require a...

  • EPSS 0.82%
  • Veröffentlicht 26.07.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leveraging a hijacked session.