OpenProject is open-source, web-based project management software. In versions prior to 15.2.1, the application fails to properly sanitize user input before displaying it in the Group Management section. Groups created with HTML script tags are not properly escaped before rendering them in a project. The issue has been resolved in OpenProject version 15.2.1. Those who are unable to upgrade may apply the patch manually.
References
Link | Resource |
---|---|
https://github.com/opf/openproject/pull/17783 | Patch |
https://github.com/opf/openproject/security/advisories/GHSA-mg4q-ghvh-cm2j | Patch Vendor Advisory |
https://patch-diff.githubusercontent.com/raw/opf/openproject/pull/17783.patch | Patch |
https://www.openproject.org/docs/release-notes/12-5-1 | Release Notes |
Configurations
History
27 Aug 2025, 02:09
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:* | |
Summary |
|
|
First Time |
Openproject openproject
Openproject |
|
References | () https://github.com/opf/openproject/pull/17783 - Patch | |
References | () https://github.com/opf/openproject/security/advisories/GHSA-mg4q-ghvh-cm2j - Patch, Vendor Advisory | |
References | () https://patch-diff.githubusercontent.com/raw/opf/openproject/pull/17783.patch - Patch | |
References | () https://www.openproject.org/docs/release-notes/12-5-1 - Release Notes |
10 Feb 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-10 16:15
Updated : 2025-08-27 02:09
NVD link : CVE-2025-24892
Mitre link : CVE-2025-24892
CVE.ORG link : CVE-2025-24892
JSON object : View
Products Affected
openproject
- openproject
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')