CVE-2024-21584: Pleasanter

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Pleasanter 1.3.49.0 and earlier contains a cross-site scripting vulnerability. If an attacker tricks the user to access the product with a specially crafted URL and perform a specific operation, an arbitrary script may be executed on the web browser of the user.

Affected products

  • Pleasanter Pleasanter: up to and including 1.3.49.0

Published 2024-03-12. Last modified 2026-06-17.