CVE-2023-32685
published 2023-05-30CVE-2023-32685: Kanboard is project management software that focuses on the Kanban methodology. Due to improper handling of elements under the `contentEditable` element…
PriorityP425medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.51%
40.3th percentile
Kanboard is project management software that focuses on the Kanban methodology. Due to improper handling of elements under the `contentEditable` element, maliciously crafted clipboard content can inject arbitrary HTML tags into the DOM. A low-privileged attacker with permission to attach a document on a vulnerable Kanboard instance can trick the victim into pasting malicious screenshot data and achieve cross-site scripting if CSP is improperly configured. This issue has been patched in version 1.2.29.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kanboard | < kanboard 1.2.26+ds-3 (forky) | kanboard 1.2.26+ds-3 (forky) |
| kanboard | kanboard | < 1.2.29 | 1.2.29 |
| kanboard | kanboard | >= 0 < 1.2.26+ds-3 | 1.2.26+ds-3 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
osv5.4MEDIUM
vendor_debian4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-32685: Kanboard is project management software that focuses on the Kanban methodology
osv·2023-05-30·CVSS 5.4
CVE-2023-32685 [MEDIUM] CVE-2023-32685: Kanboard is project management software that focuses on the Kanban methodology
Kanboard is project management software that focuses on the Kanban methodology. Due to improper handling of elements under the `contentEditable` element, maliciously crafted clipboard content can inject arbitrary HTML tags into the DOM. A low-privileged attacker with permission to attach a document on a vulnerable Kanboard instance can trick the victim into pasting malicious screenshot data and achieve cross-site scripting if CSP is improperly configured. This issue has been patched in version 1.2.29.
Debian
CVE-2023-32685: kanboard - Kanboard is project management software that focuses on the Kanban methodology. ...
vendor_debian·2023·CVSS 4.4
CVE-2023-32685 [MEDIUM] CVE-2023-32685: kanboard - Kanboard is project management software that focuses on the Kanban methodology. ...
Kanboard is project management software that focuses on the Kanban methodology. Due to improper handling of elements under the `contentEditable` element, maliciously crafted clipboard content can inject arbitrary HTML tags into the DOM. A low-privileged attacker with permission to attach a document on a vulnerable Kanboard instance can trick the victim into pasting malicious screenshot data and achieve cross-site scripting if CSP is improperly configured. This issue has been patched in version 1.2.29.
Scope: local
forky: resolved (fixed in 1.2.26+ds-3)
sid: resolved (fixed in 1.2.26+ds-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/kanboard/kanboard/commit/26b6eebb78d4306e48b836a58f7c386251aa2bc7https://github.com/kanboard/kanboard/commit/c9c187206700030c43493b80fd599b4d096cb713https://github.com/kanboard/kanboard/security/advisories/GHSA-hjmw-gm82-r4gvhttps://github.com/kanboard/kanboard/commit/26b6eebb78d4306e48b836a58f7c386251aa2bc7https://github.com/kanboard/kanboard/commit/c9c187206700030c43493b80fd599b4d096cb713https://github.com/kanboard/kanboard/security/advisories/GHSA-hjmw-gm82-r4gv
2023-05-30
Published