Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-3977 | OpenProject is open-source, web-based project management software. In versions prior to 15.2.1, the application fails to properly sanitize user input before displaying it in the Group Management section. Groups created with HTML script tags are not properly escaped before rendering them in a project. The issue has been resolved in OpenProject version 15.2.1. Those who are unable to upgrade may apply the patch manually. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 27 Aug 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:* |
Wed, 12 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Feb 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenProject is open-source, web-based project management software. In versions prior to 15.2.1, the application fails to properly sanitize user input before displaying it in the Group Management section. Groups created with HTML script tags are not properly escaped before rendering them in a project. The issue has been resolved in OpenProject version 15.2.1. Those who are unable to upgrade may apply the patch manually. | |
| Title | OpenProject stored HTML injection vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-12T15:45:38.543Z
Reserved: 2025-01-27T15:32:29.451Z
Link: CVE-2025-24892
Updated: 2025-02-12T15:45:34.404Z
Status : Analyzed
Published: 2025-02-10T16:15:39.310
Modified: 2025-08-27T02:09:35.983
Link: CVE-2025-24892
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:14Z
EUVD