PT-2023-24608 · Kanboard · Kanboard

Castilho101

·

Published

2023-06-05

·

Updated

2026-02-13

·

CVE-2023-33968

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kanboard versions prior to 1.2.30
Description Kanboard is project management software based on the Kanban methodology. A missing access control allows a user with limited privileges to create or move tasks to any project, even those they haven’t been invited to or are personal. The issue affects the Duplicate to project and Move to project features, which use the checkDestinationProjectValues() function.
Recommendations Upgrade to version 1.2.30 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-33968
GHSA-GF8R-4P6M-V8VR

Affected Products

Kanboard