An XSS vulnerability in project list in OpenProject prior to 9.0.4 and 10.x prior to 10.0.2 allows remote malicious users to inject arbitrary web script or HTML via the sortBy parameter because error messages are mishandled.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
openproject openproject |