Related Vulnerabilities: CVE-2021-29274  

Redmine 4.1.x before 4.1.2 allows cross-site scripting (XSS) because an issue's subject is mishandled in the auto complete tip.

Severity High

Remote Yes

Type Cross-site scripting

Description

Redmine 4.1.x before 4.1.2 allows cross-site scripting (XSS) because an issue's subject is mishandled in the auto complete tip.

AVG-1743 redmine 4.1.1-2 High Vulnerable FS#70203

https://www.redmine.org/issues/33846
https://github.com/redmine/redmine/commit/35f5165c2dfc0364514541d38840e12024e2bc91