Vendor CVEs
Redmine
All CVEs
58 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-31541 | Cri | 0.64 | 9.8 | 0.01 | Jun 13, 2023 | A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server. | ||
| CVE-2021-30164 | Cri | 0.64 | 9.8 | 0.01 | Apr 6, 2021 | Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API. | ||
| CVE-2024-36267 | Hig | 0.53 | 8.1 | 0.01 | May 30, 2024 | Path traversal vulnerability exists in Redmine DMSF Plugin versions prior to 3.1.4. If this vulnerability is exploited, a logged-in user may obtain or delete arbitrary files on the server (within the privilege of the Redmine process). | ||
| CVE-2022-44030 | Hig | 0.49 | 7.5 | 0.01 | Dec 6, 2022 | Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user. | ||
| CVE-2021-37156 | Hig | 0.49 | 7.5 | 0.01 | Aug 5, 2021 | Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated. | ||
| CVE-2021-31863 | Hig | 0.49 | 7.5 | 0.02 | Apr 28, 2021 | Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process. | ||
| CVE-2021-30163 | Hig | 0.49 | 7.5 | 0.01 | Apr 6, 2021 | Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values. | ||
| CVE-2017-15577 | Hig | 0.49 | 7.5 | 0.02 | Oct 18, 2017 | Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information. | ||
| CVE-2017-15576 | Hig | 0.49 | 7.5 | 0.02 | Oct 18, 2017 | Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information. | ||
| CVE-2017-15572 | Hig | 0.49 | 7.5 | 0.02 | Oct 18, 2017 | In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redirect. | ||
| CVE-2017-15575 | Hig | 0.48 | 7.3 | 0.01 | Oct 18, 2017 | In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences information or possibly have unspecified other impact. | ||
| CVE-2015-8474 | Hig | 0.41 | 7.4 | 0.02 | Apr 12, 2016 | Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, and 3.1.x before 3.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted… | ||
| CVE-2023-47260 | Med | 0.40 | 6.1 | 0.00 | Nov 5, 2023 | Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails. | ||
| CVE-2023-47259 | Med | 0.40 | 6.1 | 0.00 | Nov 5, 2023 | Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter. | ||
| CVE-2023-47258 | Med | 0.40 | 6.1 | 0.00 | Nov 5, 2023 | Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter. | ||
| CVE-2022-44637 | Med | 0.40 | 6.1 | 0.00 | Dec 12, 2022 | Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatted fields. Depending on the configuration, this may require login as a registered user. | ||
| CVE-2022-44031 | Med | 0.40 | 6.1 | 0.00 | Dec 12, 2022 | Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization of the blockquote syntax in Textile-formatted fields. | ||
| CVE-2021-29274 | Med | 0.40 | 6.1 | 0.01 | Mar 29, 2021 | Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip. | ||
| CVE-2019-15950 | Med | 0.40 | 6.1 | 0.01 | Sep 16, 2019 | The CRM Plugin before 4.2.4 for Redmine allows XSS via crafted vCard data. | ||
| CVE-2017-15574 | Med | 0.40 | 6.1 | 0.01 | Oct 18, 2017 | In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment. | ||
| CVE-2017-15573 | Med | 0.40 | 6.1 | 0.01 | Oct 18, 2017 | In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content. | ||
| CVE-2017-15571 | Med | 0.40 | 6.1 | 0.01 | Oct 18, 2017 | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data. | ||
| CVE-2017-15570 | Med | 0.40 | 6.1 | 0.01 | Oct 18, 2017 | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data. | ||
| CVE-2017-15569 | Med | 0.40 | 6.1 | 0.01 | Oct 18, 2017 | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of an issue list. | ||
| CVE-2017-15568 | Med | 0.40 | 6.1 | 0.01 | Oct 18, 2017 | In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of issue history. | ||
| CVE-2016-10515 | Med | 0.40 | 6.1 | 0.01 | Oct 18, 2017 | In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and project homepages. | ||
| CVE-2015-8477 | Med | 0.40 | 6.1 | 0.02 | May 23, 2017 | Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving flash message rendering. | ||
| CVE-2019-18890 | Med | 0.36 | 6.5 | 0.04 | Nov 21, 2019 | A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query. | ||
| CVE-2021-42326 | Med | 0.35 | 5.3 | 0.01 | Oct 12, 2021 | Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter. | ||
| CVE-2021-31866 | Med | 0.35 | 5.3 | 0.01 | Apr 28, 2021 | Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController. | ||
| CVE-2021-31865 | Med | 0.35 | 5.3 | 0.01 | Apr 28, 2021 | Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments. | ||
| CVE-2021-31864 | Med | 0.35 | 5.3 | 0.01 | Apr 28, 2021 | Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permission requirement by leveraging the incoming mail handler. | ||
| CVE-2019-25026 | Med | 0.35 | 5.3 | 0.01 | Apr 6, 2021 | Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting. | ||
| CVE-2026-1836 | Med | 0.34 | — | 0.00 | Jun 12, 2026 | The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials. | ||
| CVE-2024-37664 | Med | 0.34 | 5.2 | 0.00 | Jun 17, 2024 | Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traffic between the victim and any remote server by sending out forged TCP RST messages to evict NAT mappings in the router. | ||
| CVE-2020-36307 | Med | 0.33 | 6.1 | 0.01 | Apr 6, 2021 | Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links. | ||
| CVE-2020-36306 | Med | 0.33 | 6.1 | 0.01 | Apr 6, 2021 | Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field. | ||
| CVE-2019-17427 | Med | 0.33 | 6.1 | 0.02 | Oct 10, 2019 | In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors. | ||
| CVE-2020-36308 | Med | 0.28 | 5.3 | 0.01 | Apr 6, 2021 | Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries. | ||
| CVE-2017-16804 | Med | 0.28 | 4.3 | 0.02 | Nov 13, 2017 | In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages. | ||
| CVE-2015-8537 | Med | 0.28 | 5.3 | 0.02 | Apr 12, 2016 | app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attackers to obtain sensitive information by viewing an Atom feed. | ||
| CVE-2015-8346 | Med | 0.28 | 5.3 | 0.02 | Apr 12, 2016 | app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form. | ||
| CVE-2024-37663 | Med | 0.27 | 4.1 | 0.00 | Jun 17, 2024 | Redmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sending out forged ICMP redirect messages. | ||
| CVE-2025-4011 | Low | 0.23 | 3.5 | 0.00 | Apr 28, 2025 | A vulnerability has been found in Redmine 6.0.0/6.0.1/6.0.2/6.0.3 and classified as problematic. This vulnerability affects unknown code of the component Custom Query Handler. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated… | ||
| CVE-2015-8473 | Med | 0.21 | 4.3 | 0.02 | Apr 12, 2016 | The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects. | ||
| CVE-2011-4929 | 0.07 | — | 0.46 | Oct 8, 2012 | Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary commands via unknown vectors. | |||
| CVE-2017-18026 | Hig | 0.00 | 8.8 | 0.03 | Jan 10, 2018 | Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name… | ||
| CVE-2013-4663 | 0.00 | — | 0.02 | Dec 28, 2014 | git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the service parameter to info/refs, related to the get_info_refs function or (2) the reqfile argument to the file_exists… | |||
| CVE-2014-1985 | 0.00 | — | 0.03 | Apr 11, 2014 | Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine before 2.4.5 and 2.5.x before 2.5.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the back… | |||
| CVE-2011-4928 | 0.00 | — | 0.02 | Oct 8, 2012 | Cross-site scripting (XSS) vulnerability in the textile formatter in Redmine before 1.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
- risk 0.64cvss 9.8epss 0.01
A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.
- risk 0.64cvss 9.8epss 0.01
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.
- risk 0.53cvss 8.1epss 0.01
Path traversal vulnerability exists in Redmine DMSF Plugin versions prior to 3.1.4. If this vulnerability is exploited, a logged-in user may obtain or delete arbitrary files on the server (within the privilege of the Redmine process).
- risk 0.49cvss 7.5epss 0.01
Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.
- risk 0.49cvss 7.5epss 0.01
Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated.
- risk 0.49cvss 7.5epss 0.02
Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process.
- risk 0.49cvss 7.5epss 0.01
Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values.
- risk 0.49cvss 7.5epss 0.02
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.
- risk 0.49cvss 7.5epss 0.02
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.
- risk 0.49cvss 7.5epss 0.02
In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redirect.
- risk 0.48cvss 7.3epss 0.01
In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences information or possibly have unspecified other impact.
- risk 0.41cvss 7.4epss 0.02
Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, and 3.1.x before 3.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted…
- risk 0.40cvss 6.1epss 0.00
Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails.
- risk 0.40cvss 6.1epss 0.00
Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter.
- risk 0.40cvss 6.1epss 0.00
Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter.
- risk 0.40cvss 6.1epss 0.00
Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatted fields. Depending on the configuration, this may require login as a registered user.
- risk 0.40cvss 6.1epss 0.00
Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization of the blockquote syntax in Textile-formatted fields.
- risk 0.40cvss 6.1epss 0.01
Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip.
- risk 0.40cvss 6.1epss 0.01
The CRM Plugin before 4.2.4 for Redmine allows XSS via crafted vCard data.
- risk 0.40cvss 6.1epss 0.01
In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.
- risk 0.40cvss 6.1epss 0.01
In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.
- risk 0.40cvss 6.1epss 0.01
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.
- risk 0.40cvss 6.1epss 0.01
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data.
- risk 0.40cvss 6.1epss 0.01
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of an issue list.
- risk 0.40cvss 6.1epss 0.01
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of issue history.
- risk 0.40cvss 6.1epss 0.01
In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and project homepages.
- risk 0.40cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving flash message rendering.
- risk 0.36cvss 6.5epss 0.04
A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.
- risk 0.35cvss 5.3epss 0.01
Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
- risk 0.35cvss 5.3epss 0.01
Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.
- risk 0.35cvss 5.3epss 0.01
Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments.
- risk 0.35cvss 5.3epss 0.01
Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permission requirement by leveraging the incoming mail handler.
- risk 0.35cvss 5.3epss 0.01
Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting.
- risk 0.34cvss —epss 0.00
The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.
- risk 0.34cvss 5.2epss 0.00
Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traffic between the victim and any remote server by sending out forged TCP RST messages to evict NAT mappings in the router.
- risk 0.33cvss 6.1epss 0.01
Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links.
- risk 0.33cvss 6.1epss 0.01
Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field.
- risk 0.33cvss 6.1epss 0.02
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
- risk 0.28cvss 5.3epss 0.01
Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.
- risk 0.28cvss 4.3epss 0.02
In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.
- risk 0.28cvss 5.3epss 0.02
app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attackers to obtain sensitive information by viewing an Atom feed.
- risk 0.28cvss 5.3epss 0.02
app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form.
- risk 0.27cvss 4.1epss 0.00
Redmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sending out forged ICMP redirect messages.
- risk 0.23cvss 3.5epss 0.00
A vulnerability has been found in Redmine 6.0.0/6.0.1/6.0.2/6.0.3 and classified as problematic. This vulnerability affects unknown code of the component Custom Query Handler. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated…
- risk 0.21cvss 4.3epss 0.02
The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects.
- CVE-2011-4929Oct 8, 2012risk 0.07cvss —epss 0.46
Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary commands via unknown vectors.
- risk 0.00cvss 8.8epss 0.03
Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch whose name…
- CVE-2013-4663Dec 28, 2014risk 0.00cvss —epss 0.02
git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the service parameter to info/refs, related to the get_info_refs function or (2) the reqfile argument to the file_exists…
- CVE-2014-1985Apr 11, 2014risk 0.00cvss —epss 0.03
Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine before 2.4.5 and 2.5.x before 2.5.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the back…
- CVE-2011-4928Oct 8, 2012risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in the textile formatter in Redmine before 1.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Page 1 of 2