Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f2hf-mr43-85mv

Опубликовано: 23 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.3

Описание

WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs, create new integrations, modify or delete existing integrations, and manage integration activities by exploiting insufficient authorization checks in the JsonRoutes REST handlers.

WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs, create new integrations, modify or delete existing integrations, and manage integration activities by exploiting insufficient authorization checks in the JsonRoutes REST handlers.

EPSS

Процентиль: 20%
0.00274
Низкий

8.7 High

CVSS4

8.3 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.3
nvd
4 месяца назад

WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs, create new integrations, modify or delete existing integrations, and manage integration activities by exploiting insufficient authorization checks in the JsonRoutes REST handlers.

CVSS3: 8.3
debian
4 месяца назад

WeKan before8.35 contains a missing authorization vulnerability in the ...

EPSS

Процентиль: 20%
0.00274
Низкий

8.7 High

CVSS4

8.3 High

CVSS3

Дефекты

CWE-862