Cross-site Scripting and Directory Traversal Vulnerabilities in Pleasanter
Release date June 22, 2023
■Overview
It has been discovered that all versions of our product "Pleasanter" are vulnerable to cross-site scripting and directory traversal. If this vulnerability is exploited, there is a risk that malicious third parties may redirect users to external fraudulent sites or leak or tamper with data registered in Pleasanter.
The versions of Pleasanter affected by this issue are listed below. Please take the measures listed in the countermeasures.
■How to check the affected version
The affected versions are as follows:
・All versions prior to 1.3.39.2
*This applies to both Community Edition and Enterprise Edition.
*This also applies to versions 1.2, 1.1, 0.51, 0.50, 0.49 and earlier.
・Please, refer to the following user manual for how to check the version.
"FAQ: I want to check the version of Pleasanter"
■Vulnerability description
When a logged-in general user pastes an image in the content, explanation column, comment, etc., or attaches a file to the attachment column, the request is fraudulently altered to lead to an external site or script provided by Pleasanter. A vulnerability allows the user to execute, and upload files to unexpected folders. Anonymous users who cannot log in to Pleasanter cannot perform attacks using this vulnerability.
■Threat posed by vulnerabilities
The script installed by the attacker may lead to malicious external sites, or if the manager of Pleasanter opens a page where the attacker installed the script, it may unintentionally cause the manager of Pleasanter to execute administrative operations on Pleasanter. Files may also be saved to unexpected folders.
■Countermeasure
・For customers using versions 1.3.X, 1.2.X, 1.1.X, 0.51.X, 0.50.X, 0.49.X or earlier
Please upgrade to the latest version, 1.3.40.0 or later (released June 6, 2023), which contains the fix.
* Individual patches will not be provided to address the issue without upgrading.
・For customers using a dedicated environment
We will update the version as soon as possible after adjusting the schedule separately.(Restart is required.)
■Change log
2023.6.22 This vulnerability has been made public.
■Contact information
If you have any questions, Please contact us via the form below.
Inquiry form
https://pleasanter.org/contact/