OrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into user email due to lack of input validation, which could lead to account takeover.
History

Tue, 30 Sep 2025 21:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:orangescrum:orangescrum:2.0.11:*:*:*:*:*:*:*

Wed, 22 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jan 2025 21:00:00 +0000

Type Values Removed Values Added
Description OrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into user email due to lack of input validation, which could lead to account takeover.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-01-21T00:00:00.000Z

Updated: 2025-01-22T21:53:34.918Z

Reserved: 2024-10-08T00:00:00.000Z

Link: CVE-2024-48392

cve-icon Vulnrichment

Updated: 2025-01-22T21:53:28.669Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-21T21:15:10.837

Modified: 2025-09-30T21:01:01.977

Link: CVE-2024-48392

cve-icon Redhat

No data.