Kanboard is project management software that focuses on the Kanban methodology. Due to improper handling of elements under the `contentEditable` element, maliciously crafted clipboard content can inject arbitrary HTML tags into the DOM. A low-privileged attacker with permission to attach a document on a vulnerable Kanboard instance can trick the victim into pasting malicious screenshot data and achieve cross-site scripting if CSP is improperly configured. This issue has been patched in version 1.2.29.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-05-30T04:11:50.569Z
Updated: 2024-08-02T15:25:36.755Z
Reserved: 2023-05-11T16:33:45.732Z
Link: CVE-2023-32685
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-05-30T05:15:11.770
Modified: 2024-11-21T08:03:50.883
Link: CVE-2023-32685
Redhat
No data.