Cross-site Scripting and Directory Traversal Vulnerabilities in Pleasanter

Release date June 22, 2023


■Overview

It has been discovered that all versions of our product "Pleasanter" are vulnerable to cross-site scripting and directory traversal. If this vulnerability is exploited, there is a risk that malicious third parties may redirect users to external fraudulent sites or leak or tamper with data registered in Pleasanter.

The versions of Pleasanter affected by this issue are listed below. Please take the measures listed in the countermeasures.


■How to check the affected version

The affected versions are as follows:

・All versions prior to 1.3.39.2

 *This applies to both Community Edition and Enterprise Edition.

 *This also applies to versions 1.2, 1.1, 0.51, 0.50, 0.49 and earlier.

・Please, refer to the following user manual for how to check the version.

 "FAQ: I want to check the version of Pleasanter"


■Vulnerability description

When a logged-in general user pastes an image in the content, explanation column, comment, etc., or attaches a file to the attachment column, the request is fraudulently altered to lead to an external site or script provided by Pleasanter. A vulnerability allows the user to execute, and upload files to unexpected folders. Anonymous users who cannot log in to Pleasanter cannot perform attacks using this vulnerability.


■Threat posed by vulnerabilities

The script installed by the attacker may lead to malicious external sites, or if the manager of Pleasanter opens a page where the attacker installed the script, it may unintentionally cause the manager of Pleasanter to execute administrative operations on Pleasanter. Files may also be saved to unexpected folders.


■Countermeasure

・For customers using versions 1.3.X, 1.2.X, 1.1.X, 0.51.X, 0.50.X, 0.49.X or earlier

 Please upgrade to the latest version, 1.3.40.0 or later (released June 6, 2023), which contains the fix.

 * Individual patches will not be provided to address the issue without upgrading.

・For customers using a dedicated environment

 We will update the version as soon as possible after adjusting the schedule separately.(Restart is required.)


■Change log

2023.6.22 This vulnerability has been made public.


■Contact information

If you have any questions, Please contact us via the form below.

Inquiry form

https://pleasanter.org/contact/