CVE-2025-28254

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Mar 28, 2025
Updated: Apr 7, 2025
CWE ID 79

Summary

CVE-2025-28254 is a Cross-Site Scripting (XSS) vulnerability affecting Leantime, an open-source project management tool. In versions 3.2.1 and prior, an authenticated attacker can exploit the vulnerability in the processMentions() function by injecting malicious code into the first name field. Successful exploitation enables the attacker to execute arbitrary code and potentially obtain sensitive information from affected users. This vulnerability poses a significant risk, especially in organizations that rely on Leantime for managing sensitive projects and data. It is recommended that users upgrade to the latest version of Leantime as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share