PT-2023-24608 · Kanboard · Kanboard

Castilho101

·

Publicado

2023-06-05

·

Atualizado

2026-02-13

·

CVE-2023-33968

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kanboard versions prior to 1.2.30
Description Kanboard is project management software based on the Kanban methodology. A missing access control allows a user with limited privileges to create or move tasks to any project, even those they haven’t been invited to or are personal. The issue affects the Duplicate to project and Move to project features, which use the checkDestinationProjectValues() function.
Recommendations Upgrade to version 1.2.30 or later.

Exploit

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-33968
GHSA-GF8R-4P6M-V8VR

Produtos afetados

Kanboard