← Back

CVE-2024-54001

nvd nist
Published: Dec 5, 2024Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the application settings section. The fields application_language, application_date_format,application_timezone and application_time_format allow arbirary user input which is reflected. The vulnerability can become xss if the user input is javascript code that bypass CSP. This vulnerability is fixed in 1.2.41.

Affected (1)

Products: Kanboard: Kanboard
1 product
Kanboard
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.2.40

References (1)

Source: security-advisories@github.com
ExploitVendor Advisory

Timeline

No history available yet.