Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f95x-r3pv-jh63

Опубликовано: 15 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.2
CVSS3: 8.1

Описание

Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the attacker-supplied project_id but never verifies that the supplied task_id actually belongs to that project. Because task identifiers are sequential integers shared across the entire instance, any authenticated user who is a member of at least one project can enumerate and move (corrupt/hide) tasks belonging to any other project on the same instance, including private projects they have no membership or role on.

Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the attacker-supplied project_id but never verifies that the supplied task_id actually belongs to that project. Because task identifiers are sequential integers shared across the entire instance, any authenticated user who is a member of at least one project can enumerate and move (corrupt/hide) tasks belonging to any other project on the same instance, including private projects they have no membership or role on.

EPSS

Процентиль: 28%
0.00355
Низкий

7.2 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.1
nvd
22 дня назад

Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the attacker-supplied project_id but never verifies that the supplied task_id actually belongs to that project. Because task identifiers are sequential integers shared across the entire instance, any authenticated user who is a member of at least one project can enumerate and move (corrupt/hide) tasks belonging to any other project on the same instance, including private projects they have no membership or role on.

CVSS3: 8.1
debian
22 дня назад

Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController ...

EPSS

Процентиль: 28%
0.00355
Низкий

7.2 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-639