{"id":"GHSA-mg4c-884j-pcq9","aliases":[],"url":"https://o3.security/vulnerability/GHSA-mg4c-884j-pcq9","summary":"Leantime allows Stored Cross-Site Scripting (XSS)","details":"STORED XSS +OPEN REDIRECTION in SVG uploads\nVulnerable url:https://hack.leantime.io/projects/showProject/3","published":"2025-02-21T22:14:58Z","modified":"2025-02-21T22:26:34.328094Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"leantime/leantime","fixedVersion":"3.3"}],"fix":{"url":"https://github.com/Leantime/leantime/commit/d8b1099b0629da64ad30a1c4daee104fadc6c227","label":"Leantime/leantime@d8b1099"},"references":[{"type":"WEB","url":"https://github.com/Leantime/leantime/security/advisories/GHSA-mg4c-884j-pcq9"},{"type":"WEB","url":"https://github.com/Leantime/leantime/commit/d8b1099b0629da64ad30a1c4daee104fadc6c227"},{"type":"PACKAGE","url":"https://github.com/Leantime/leantime"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-02-21T22:26:34.328094Z"}}