OpenProject
cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*
- >= 16.3.0, <= 16.6.4
A stored cross-site scripting vulnerability has been identified in OpenProject, affecting versions 16.3.0 prior to 16.6.5. The issue arises in the Roadmap view, where the 'Related work packages' list can include work packages from different projects. The vulnerability occurs because project names, which are user-controlled, are not properly escaped before being rendered as HTML. This allows any HTML injected into a subproject name to be executed on the page.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
Users can upgrade to OpenProject versions 16.6.5 or 17.0.0, both of which include the necessary patch. For those unable to upgrade, it is recommended to add a 'X-Content-Type-Options: nosniff' header in the proxying web application server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.