mediumCVSS 5.4Vulnerability

GHSA-qrfh-cc86-vc8c

### Summary Leantime v2.3.27 is vulnerable to Stored HTML Injection. The `firstname` and `lastname` fields in the admin user edit page are rendered without HTML escaping, allowing an authenticated user to inject arbitrary HTML that executes when the profile is viewed. ### Vulnerable File `app/Domain/Users/Templates/editUser.tpl.php` ### Vulnerable Code (Lines ~14-17) ```php value="<?php echo $values['firstname'] ?>" value="<?php echo $values['lastname'] ?>" ``` These fields output raw user input without sanitization. ### Steps to Reproduce 1. Login as admin > Go to Settings > Users > Edit any user 2. Enter HTML payload in First Name or Last Name field: `<h1>INJECTED</h1>` 3. Save the user profile 4. Create or view an article — the injected HTML renders in the author name ### Fix Replace unescaped `echo` with `htmlspecialchars()`: ```php value="<?php echo htmlspecialchars($values['firstname'], ENT_QUOTES, 'UTF-8') ?>" value="<?php echo htmlspecialchars($values['lastname'], ENT_QUOTES, 'UTF-8') ?>" ``` Or use the existing `$this->e()` helper already used in `editOwn.tpl.php`. ### Impact - Stored HTML injection visible to all users viewing affected content - Can be used for phishing, fake login forms, and UI defacement - Affects all versions before 3.3.0

Properties

ghsa_id
GHSA-qrfh-cc86-vc8c
severity
medium
summary
Leantime has HTML injection through firstname and lastname fields
cvss_score
5.4
cve_id
GHSA-qrfh-cc86-vc8c
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
is_ghsa_only
true
ghsa_published
2026-03-05T18:05:57Z
source_url
https://github.com/advisories/GHSA-qrfh-cc86-vc8c
ghsa_updated
2026-03-05T18:05:59Z

Related Entities (3)

AFFECTS (1)

[Software]composer/leantime/leantime

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-qrfh-cc86-vc8c (CVSS 5.4) — Ninja Signal Threat Intelligence | Ninja Signal