CVE-2025-4011
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Apr 28, 2025
Updated: Apr 29, 2025
CWE ID 129
Summary
CVE-2025-4011 is a newly discovered vulnerability affecting Redmine versions 6.0.0 through 6.0.3. This issue is classified as problematic and lies within the Custom Query Handler component's unknown code. The exploitation of this vulnerability occurs when the Name argument is manipulated, resulting in cross-site scripting. The attack can be initiated remotely, making it potentially dangerous. Upgrading to Redmine version 6.0.4 is the recommended solution to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX