{"id":"GHSA-f679-254h-qhvj","aliases":[],"url":"https://o3.security/vulnerability/GHSA-f679-254h-qhvj","summary":"Leantime allows Cross-Site Scripting (XSS)","details":"### Summary\nThere is a cross-site scripting vulnerability on To-Do that affects a title field of a To-Do.","published":"2025-02-21T23:54:31Z","modified":"2025-02-22T00:25:28.870500Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"leantime/leantime","fixedVersion":"3.3"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/Leantime/leantime/security/advisories/GHSA-f679-254h-qhvj"},{"type":"PACKAGE","url":"https://github.com/Leantime/leantime"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-02-22T00:25:28.870500Z"}}