Leantime allows Stored Cross-Site Scripting (XSS)
Moderate severity
GitHub Reviewed
Published
Feb 18, 2025
in
Leantime/leantime
•
Updated Feb 21, 2025
Description
Published to the GitHub Advisory Database
Feb 21, 2025
Reviewed
Feb 21, 2025
Last updated
Feb 21, 2025
STORED XSS +OPEN REDIRECTION in SVG uploads
Vulnerable url:https://hack.leantime.io/projects/showProject/3
References