← Back

CVE-2025-28254

nvd nist
Published: Mar 28, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Cross Site Scripting vulnerability in Leantime v3.2.1 and before allows an authenticated attacker to execute arbitrary code and obtain sensitive information via the first name field in processMentions().

Affected (1)

Products: Leantime: Leantime
1 product
Leantime
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.3.0

Timeline

No history available yet.