Devaslanphp · Project-Management · CVE-2026-10285
**Name of the Vulnerable Software and Affected Versions**
DevaslanPHP project-management versions prior to 2.0.0-beta1
**Description**
An improper authorization issue exists in the Ticket Handler component. A remote attacker can exploit this by manipulating the `recordUpdated()` function within the `app/Helpers/KanbanScrumHelper.php` file.
**Recommendations**
As a temporary workaround, restrict access to the `recordUpdated()` function in the `app/Helpers/KanbanScrumHelper.php` file until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.