← Back to CVE List

CVE-2024-54001

Published: 2024-12-05T16:15Z
Last Modified: 2025-03-10T17:06Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the application settings section. The fields application_language, application_date_format,application_timezone and application_time_format allow arbirary user input which is reflected. The vulnerability can become xss if the user input is javascript code that bypass CSP. This vulnerability is fixed in 1.2.41. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt