PT-2025-51221 · Wekan · Wekan

Siam Thanat Hack

+1

·

Published

2025-12-15

·

Updated

2025-12-15

·

CVE-2025-65782

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Wekan versions prior to 18.16
Description An authorization flaw exists in the card update handling process. This flaw allows board members, and potentially other authenticated users, to manipulate user IDs within the vote.positive and vote.negative arrays. This manipulation enables vote forgery and unauthorized voting. The affected system is an open-source kanban board.
Recommendations Update to version 18.16 or later.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-65782

Affected Products

Wekan