PT-2025-51219 · Wekan · Wekan
Siam Thanat Hack
+1
·
Publicado
2025-12-15
·
Atualizado
2025-12-15
·
CVE-2025-65780
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wekan versions prior to 18.16
Description
Authenticated users can modify their entire user document, including organization and team memberships, and login status, due to insufficient server-side authorization checks. This allows for privilege escalation and unauthorized access to other teams and organizations.
Recommendations
Update to version 18.16 or later.
Correção
LPE
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wekan