CVE-2025-24892 is a medium-severity cross-site scripting (XSS) vulnerability affecting OpenProject versions prior to 15.2.1. The flaw allows an authenticated attacker to inject malicious HTML script tags into group names, which are then rendered unescaped in the Group Management section, potentially leading to client-side code execution. The CVSS score of 5.4 indicates a network-based attack with low privileges and user interaction required, resulting in low impact to confidentiality and integrity. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.2.1CPE matchmatch criteria | cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.