Description
Orangescrum 1.8.0 contains multiple cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts through various input parameters. Attackers can exploit parameters like 'projid', 'CS_message', and 'name' to execute arbitrary JavaScript code in victim's browsers by submitting crafted payloads through application endpoints.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Hubert Wojciechowski
References
www.exploit-db.com/exploits/50554 (ExploitDB-50554)
www.orangescrum.org/ (Official Orangescrum Product Homepage)
www.vulncheck.com/...e-scripting-via-authenticated-endpoints (VulnCheck Advisory: Orangescrum 1.8.0 Cross-Site Scripting via Authenticated Endpoints)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.