Junglewise Threat Intelligence

CVE-2024-13073: Akinsoft TaskPano cross-site scripting

CVE-2024-13073 · Severity: medium · CVSS 4.7 · Published 2025-09-04

Vendors: AKINSOFT.

Executive brief

Akinsoft TaskPano, a project and task management platform, contains a security vulnerability that allows for cross-site scripting. An attacker with high-level administrative privileges can inject malicious scripts into the application's web pages. This could lead to unauthorized actions being performed in the context of other users' sessions or the theft of sensitive information within the platform.

Technical details

Akinsoft TaskPano version s1.06.04 is vulnerable to Cross-Site Scripting (XSS) classified under CWE-79. The vulnerability stems from the improper neutralization of user-supplied input during the generation of web pages, allowing an attacker to inject arbitrary JavaScript. According to the CVSS metrics, the attack requires high privileges (PR:H) but no user interaction (UI:N), suggesting a stored XSS vector where an administrator can persist a payload that executes in the browsers of other users. Successful exploitation can impact the confidentiality, integrity, and availability of the application session.

Affected products

  • Akinsoft TaskPano s1.06.04

Timeline

  • 2025-09-04: advisory: Initial disclosure by TR-CERT/USOM

References

Related threats