CVE-2017-15574
published 2017-10-18CVE-2017-15574: In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.
PriorityP424medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.14%
62.9th percentile
In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | redmine | < redmine 3.4.2-1 (bookworm) | redmine 3.4.2-1 (bookworm) |
| redmine | redmine | <= 3.2.5 | — |
| redmine | redmine | — | — |
| redmine | redmine | — | — |
| redmine | redmine | — | — |
| redmine | redmine | >= 0 < 3.4.2-1 | 3.4.2-1 |
| redmine | redmine | >= 0 < 3.4.2-1 | 3.4.2-1 |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-53jw-c37j-c2h4: In Redmine before 3
ghsa_unreviewed·2022-05-14
CVE-2017-15574 [MEDIUM] CWE-79 GHSA-53jw-c37j-c2h4: In Redmine before 3
In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.
OSV
CVE-2017-15574: In Redmine before 3
osv·2017-10-18·CVSS 6.1
CVE-2017-15574 [MEDIUM] CVE-2017-15574: In Redmine before 3
In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.
Debian
CVE-2017-15574: redmine - In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using ...
vendor_debian·2017·CVSS 6.1
CVE-2017-15574 [MEDIUM] CVE-2017-15574: redmine - In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using ...
In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.
Scope: local
bookworm: resolved (fixed in 3.4.2-1)
sid: resolved (fixed in 3.4.2-1)
trixie: resolved (fixed in 3.4.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-10-18
Published