CVE-2024-35224

7.6 HIGH
Published: May 23, 2024 Modified: February 13, 2026
View on NVD

Description

OpenProject is the leading open source project management software. OpenProject utilizes `tablesorter` inside of the Cost Report feature. This dependency, when misconfigured, can lead to Stored XSS via `{icon}` substitution in table header values. This attack requires the permissions "Edit work packages" as well as "Add attachments". A project admin could attempt to escalate their privileges by sending this XSS to a System Admin. Otherwise, if a full System Admin is required, then this attack is significantly less impactful. By utilizing a ticket's attachment, you can store javascript in the application itself and bypass the application's CSP policy to achieve Stored XSS. This vulnerability has been patched in version(s) 14.1.0, 14.0.2 and 13.4.2.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://github.com/opf/openproject/security/advisories/GHSA-h26c-j8wg-frjc
Source: security-advisories@github.com
Patch Vendor Advisory
https://community.openproject.org/projects/openproject/work_packages/55198/relations
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
https://github.com/opf/openproject/security/advisories/GHSA-h26c-j8wg-frjc
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory

4 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.6 / 10.0
EPSS (Exploit Probability)
0.2%
43th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

openproject