Published: 18/10/2017 Updated: 14/03/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

In Redmine prior to 3.2.6 and 3.3.x prior to 3.3.3, stored XSS is possible by using an SVG document as an attachment.

Vendor Advisories

Multiple vulnerabilities were discovered in Redmine, a project management web application They could lead to remote code execution, information disclosure or cross-site scripting attacks For the stable distribution (stretch), these problems have been fixed in version 331-4+deb9u1 We recommend that you upgrade your redmine packages In addition ...