Orangescrum 1.8.0 contains multiple cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts through various input parameters. Attackers can exploit parameters like 'projid', 'CS_message', and 'name' to execute arbitrary JavaScript code in victim's browsers by submitting crafted payloads through application endpoints.
Metrics
Affected Vendors & Products
References
History
Tue, 23 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Orangescrum 1.8.0 contains multiple cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts through various input parameters. Attackers can exploit parameters like 'projid', 'CS_message', and 'name' to execute arbitrary JavaScript code in victim's browsers by submitting crafted payloads through application endpoints. | |
| Title | Orangescrum 1.8.0 Cross-Site Scripting via Authenticated Endpoints | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-23T19:35:40.507Z
Reserved: 2025-12-05T19:10:29.047Z
Link: CVE-2021-47716
No data.
Status : Received
Published: 2025-12-23T20:15:43.377
Modified: 2025-12-23T20:15:43.377
Link: CVE-2021-47716
No data.
OpenCVE Enrichment
No data.