Impact
A stored cross‑site scripting flaw exists in the Status Labels of the Hyve5 Leantime Project Dashboard. The vulnerability allows an attacker who obtains the required "EDIT" permissions to inject malicious content into a label name. When that label is rendered on the dashboard, the executes the injected script in the context of any user that views the project. Such a scenario can lead to session hijacking, credential theft, and broader privilege escalation across the application.
Affected Systems
Hyve5 Leantime, versions up to 3.9.8, as identified by the CNA data. The flaw resides in the file /app/Domain/Dashboard/Templates/show.blade.php and affects all installations using the vulnerable component.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate impact, with the EPSS score not available and the vulnerability not listed in CISA KEV. The attack can be performed from remote, given that an attacker can create or modify a label after gaining edit privileges. Because the flaw stores malicious code and it is rendered for any dashboard viewer, a single compromised user can trigger the cross‑site scripting for all other users, implying a wide availability of the attack path.
OpenCVE Enrichment