Implem Pleasanter Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Pleasanter, a product by Implem Inc., affecting version 1.4.20.0 and earlier. This vulnerability allows an attacker to execute arbitrary scripts in the web browsers of logged-in users. The issue arises in the Body, Description, and Comments sections, where scripts can be embedded and executed.

Impact

Exploitation of this vulnerability allows for the execution of arbitrary scripts in the web browsers of logged-in users, potentially leading to unauthorized actions being performed on behalf of the user.

Remediation

Users are advised to update Pleasanter to version 1.4.21.0 or later, which addresses this vulnerability. Instructions for updating are available on the Pleasanter website.

Added: Oct 24, 2025, 6:19 AM
Updated: Oct 24, 2025, 6:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
1.7
exploitability
5.0
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.