CVE-2024-27477
MEDIUM 6.1EPSS 0.6%
In Leantime 3.0.6, a Cross-Site Scripting vulnerability exists within the ticket creation and modification functionality, allowing attackers to inject malicious JavaScript code into the title field of tickets (also known as to-dos). This stored XSS vulnerability can be exploited to perform Server-Side Request Forgery (SSRF) attacks.
- CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS
- 0.63% chance of exploitation in the next 30 days, 48th percentile
- Published
- 2024-04-10
- Updated
- 2024-11-06
Proof-of-concept exploits (2)
- dead1nfluence/Leantime-POC0★ · 2025-08-20
- https://www.vicarius.io/vsociety/posts/analyzing-leantime-xss-for-the-fun-time-diving-int…