{ "id": "CVE-2023-31779", "sourceIdentifier": "cve@mitre.org", "published": "2023-05-22T13:15:09.913", "lastModified": "2023-05-22T13:21:34.157", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in \"Reaction to comment\" feature." } ], "metrics": {}, "references": [ { "url": "https://github.com/wekan/wekan/blob/master/CHANGELOG.md", "source": "cve@mitre.org" }, { "url": "https://github.com/wekan/wekan/commit/47ac33d6c234359c31d9b5eae49ed3e793907279", "source": "cve@mitre.org" } ] }