XSS Vulnerability in Redmine 1.0.1 to 1.1.1

0
58

Posted by Netsparker Advisories on Apr 06

Information
——————–
Name : XSS vulnerability in Redmine
Software : all Redmine versions from 1.0.1 to 1.1.1
Vendor Homepage : http://www.redmine.org
Vulnerability Type : Cross-Site Scripting
Severity : High
Researcher : Mesut Timur <mesut [at] mavitunasecurity [dot] com>
Advisory Reference : NS-11-004

Description
——————
Redmine is a flexible project management web application written using
Ruby on Rails…

Source: XSS Vulnerability in Redmine 1.0.1 to 1.1.1