#VU45118 Cross-site scripting in Redmine - CVE-2011-1723
Published: April 19, 2011 / Updated: October 11, 2021
Redmine
Ruby
Description
Vulnerability allows a remote attacker to perform Cross-site scripting attacks.
An input validation error exists in app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 when processing PATH_INFO to projects/hg-helloworld/news/. NOTE: some of these details are obtained from third party information. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Remediation
External links
- http://osvdb.org/71564
- http://secunia.com/advisories/43999
- http://securityreason.com/securityalert/8211
- http://www.mavitunasecurity.com/XSS-vulnerability-in-Redmine/
- http://www.redmine.org/news/53
- http://www.securityfocus.com/archive/1/517355/100/0/threaded
- http://www.securityfocus.com/bid/47193
- http://www.vupen.com/english/advisories/2011/0895
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66612