1 results (0.001 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

The CRM Plugin before 4.2.4 for Redmine allows XSS via crafted vCard data. El plugin CRM versiones anteriores a 4.2.4 para Redmine, permite un ataque de tipo XSS por medio de datos vCard diseñados. • https://github.com/zerohax/RedmineUP-XSS/blob/master/vcard-upload-xss https://www.redmineup.com/pages/plugins/crm/updates • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •