OpenProject是OpenProject开源的一个基于Web的项目管理软件。 OpenProject 17.2.0之前版本存在跨站脚本漏洞,该漏洞源于OpenProject的Markdown渲染验证不当,特别是在超链接处理中,可能导致攻击者注入执行DOM破坏的恶意超链接有效载荷,从而崩溃或清空整个页面。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| opf | openproject | < 17.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-30234 | 6.5 MEDIUM | OpenProject BIM BCF XML Import: <Snapshot> Path Traversal Leads to Arbitrary Local File Re |
| CVE-2026-30239 | 6.5 MEDIUM | OpenProject has a Permission Check bypass on Budget deletion allows reassignment of WorkPa |
| CVE-2026-30236 | 4.3 MEDIUM | OpenProject users that are not project members can be used to calculate Labor Budget, leak |
| CVE-2026-31974 | 3.0 LOW | Blind SSRF on OpenProject instance via webhooks |
No comments yet