NA

CVE-2023-32685

Published: 30/05/2023 Updated: 07/06/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Kanboard is project management software that focuses on the Kanban methodology. Due to improper handling of elements under the `contentEditable` element, maliciously crafted clipboard content can inject arbitrary HTML tags into the DOM. A low-privileged attacker with permission to attach a document on a vulnerable Kanboard instance can trick the victim into pasting malicious screenshot data and achieve cross-site scripting if CSP is improperly configured. This issue has been patched in version 1.2.29.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kanboard kanboard

Vendor Advisories

Debian Bug report logs - #1036874 kanboard: CVE-2023-32685 Package: src:kanboard; Maintainer for src:kanboard is Joseph Nahmias <jello@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 28 May 2023 13:33:02 UTC Severity: important Tags: pending, security, upstream Found in version kanboard ...