{"id":"CVE-2024-35224","summary":"Stored Cross-Site Scripting (XSS) in OpenProject","details":"OpenProject is the leading open source project management software. OpenProject utilizes `tablesorter` inside of the Cost Report feature. This dependency, when misconfigured, can lead to Stored XSS via `{icon}` substitution in table header values. This attack requires the permissions \"Edit work packages\" as well as \"Add attachments\". A project admin could attempt to escalate their privileges by sending this XSS to a System Admin. Otherwise, if a full System Admin is required, then this attack is significantly less impactful. By utilizing a ticket's attachment, you can store javascript in the application itself and bypass the application's CSP policy to achieve Stored XSS. This vulnerability has been patched in version(s) 14.1.0, 14.0.2 and 13.4.2.\n","aliases":["GHSA-h26c-j8wg-frjc"],"modified":"2026-08-12T03:51:19.039637818Z","published":"2024-05-23T12:53:04.336Z","database_specific":{"cwe_ids":["CWE-80"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/35xxx/CVE-2024-35224.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://community.openproject.org/projects/openproject/work_packages/55198/relations"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/35xxx/CVE-2024-35224.json"},{"type":"ADVISORY","url":"https://github.com/opf/openproject/security/advisories/GHSA-h26c-j8wg-frjc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35224"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opf/openproject","events":[{"introduced":"0"},{"fixed":"540f21f479f0c76e08e7d9e335ba41490c6eb4a2"},{"introduced":"aa7a72a913cb619b3f976ff5f411ef7af97b6caa"},{"fixed":"462d76a2a9ffe83f2cbee74bdbe3e756cfd6a646"},{"introduced":"4e5f609f07c05a82f62e66766a1d841a6121205d"},{"last_affected":"4e5f609f07c05a82f62e66766a1d841a6121205d"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:*","cpe:2.3:a:openproject:openproject:14.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"13.4.2"},{"introduced":"14.0.0"},{"fixed":"14.0.2"},{"introduced":"14.1.0"},{"last_affected":"14.1.0"}]}}],"versions":["14.1.0","v14.1.0","v14.0.1","v13.4.1","v14.0.0","v13.4.0","v13.3.1","v13.3.0","v13.2.1","v13.2.0","v13.1.2","v13.1.1","v13.1.0","v13.0.8","v13.0.7","v13.0.6","v13.0.5","v13.0.4","v13.0.3","v13.0.2","v13.0.1","v13.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-35224.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"}]}