{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-27T19:22:27.538","vulnerabilities":[{"cve":{"id":"CVE-2008-4481","sourceIdentifier":"cve@mitre.org","published":"2008-10-08T02:00:01.220","lastModified":"2026-04-23T00:35:47.467","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in Redmine 0.7.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."},{"lang":"es","value":"Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en Redmine 0.7.2 y versiones anteriores que permite a los atacantes remotos inyectar arbitrariamente una secuencia de comandos web o HTML a través de vectores no especificados."}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:*:*:*:*:*:*:*:*","versionEndIncluding":"0.7.2","matchCriteriaId":"64580467-2FAB-4103-9F61-BC398C575B0D"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.1.0:*:*:*:*:*:*:*","matchCriteriaId":"DCCB74CF-B69C-4ACF-B676-17082D54A769"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.2.1:*:*:*:*:*:*:*","matchCriteriaId":"D0254A2D-10A5-4843-BE58-72A3B5284DB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.2.2:*:*:*:*:*:*:*","matchCriteriaId":"E19773B3-33A6-439A-93BB-1FB4FA86D4D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.3.0:*:*:*:*:*:*:*","matchCriteriaId":"1314065B-1B7A-41BC-89F2-EAEE8EA8A6BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.4.0:*:*:*:*:*:*:*","matchCriteriaId":"F0BE09F2-954D-4A3E-B2D1-981EEF6AD0CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.4.1:*:*:*:*:*:*:*","matchCriteriaId":"FBEA2E09-2CA8-4999-A841-02A8488F851A"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.4.2:*:*:*:*:*:*:*","matchCriteriaId":"F99DB71A-FBBE-4FFF-8EC6-D0EDAE8EDEF3"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.5.0:*:*:*:*:*:*:*","matchCriteriaId":"CF1E2430-4FFB-4AB4-A2BD-55711486D257"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.5.1:*:*:*:*:*:*:*","matchCriteriaId":"0026FFCE-D748-41F4-B4E8-9852B3ED9532"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.6.0:*:*:*:*:*:*:*","matchCriteriaId":"554098E4-A9E5-4153-B8CD-8C987B7A8527"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.6.1:*:*:*:*:*:*:*","matchCriteriaId":"117F62E1-BEC6-416F-AD68-BC1AA260CC1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.6.2:*:*:*:*:*:*:*","matchCriteriaId":"086659CB-5DD4-4B19-8223-76A85DF82D46"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.6.3:*:*:*:*:*:*:*","matchCriteriaId":"1850A5B4-747D-4D6F-B625-7DE4857790E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.6.4:*:*:*:*:*:*:*","matchCriteriaId":"5FDE853B-C003-4C9F-9A00-AF84CCD0A05F"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.7.0:*:*:*:*:*:*:*","matchCriteriaId":"E235F356-CE27-4CFC-A064-D93E3FE0C7AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.7.0:rc1:*:*:*:*:*:*","matchCriteriaId":"7F66B7C8-0D70-4E53-90BC-938101BEB3B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:redmine:redmine:0.7.1:*:*:*:*:*:*:*","matchCriteriaId":"D4EDE791-F1E6-4E9C-9924-9AA8A34A2D36"}]}]}],"references":[{"url":"http://jvn.jp/en/jp/JVN00945448/index.html","source":"cve@mitre.org"},{"url":"http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000038.html","source":"cve@mitre.org"},{"url":"http://www.redmine.org/wiki/redmine/Changelog","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/30241","source":"cve@mitre.org","tags":["Patch"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43884","source":"cve@mitre.org"},{"url":"http://jvn.jp/en/jp/JVN00945448/index.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000038.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.redmine.org/wiki/redmine/Changelog","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/30241","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43884","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}