Leantime affected by Improper Neutralization of HTML Tags
Moderate severity
GitHub Reviewed
Published
Feb 18, 2025
in
Leantime/leantime
•
Updated Feb 21, 2025
Description
Published to the GitHub Advisory Database
Feb 21, 2025
Reviewed
Feb 21, 2025
Last updated
Feb 21, 2025
Summary
HTML can be arbitrarily injected into emails from Leantime due to improper neutralization of HTML tags in users' first names. This effectively allows for the creation of phishing emails from a Leantime instance's email address.
References