Orangescrum 1.8.0 contains multiple cross-site scripting...
Moderate severity
Unreviewed
Published
Dec 23, 2025
to the GitHub Advisory Database
•
Updated Dec 23, 2025
Description
Published by the National Vulnerability Database
Dec 23, 2025
Published to the GitHub Advisory Database
Dec 23, 2025
Last updated
Dec 23, 2025
Orangescrum 1.8.0 contains multiple cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts through various input parameters. Attackers can exploit parameters like 'projid', 'CS_message', and 'name' to execute arbitrary JavaScript code in victim's browsers by submitting crafted payloads through application endpoints.
References