Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rfrj-m942-5pqh

Опубликовано: 15 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a board's "sort" value (Boards.allow returns true without verifying userId), allowing arbitrary reordering of boards.

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a board's "sort" value (Boards.allow returns true without verifying userId), allowing arbitrary reordering of boards.

EPSS

Процентиль: 23%
0.00075
Низкий

7.5 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a board's "sort" value (Boards.allow returns true without verifying userId), allowing arbitrary reordering of boards.

EPSS

Процентиль: 23%
0.00075
Низкий

7.5 High

CVSS3

Дефекты

CWE-284