PT-2026-6762 · Unknown · Openproject

Asoticdin

·

Publicado

2026-02-06

·

Atualizado

2026-02-06

·

CVE-2026-24776

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenProject versions prior to 17.0.2
Description OpenProject is a web-based project management software. A flaw existed in the drag-and-drop functionality for agenda items, where the system did not verify if the target meeting section belonged to the same meeting. This allowed an attacker to move agenda items into different meetings, potentially causing confusion, but did not grant access to those meetings. The issue involved the drag&drop handler and its handling of meeting sections, specifically when moving an agenda item to a different section.
Recommendations Update to version 17.0.2 or later.

Exploit

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24776
GHSA-P9V8-W9PH-HQMF

Produtos afetados

Openproject