Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-36813

Опубликовано: 05 июл. 2023
Источник: nvd
CVSS3: 7.1
CVSS3: 8.8
EPSS Низкий

Описание

Kanboard is project management software that focuses on the Kanban methodology. In versions prior to 1.2.31authenticated user is able to perform a SQL Injection, leading to a privilege escalation or loss of confidentiality. It appears that in some insert and update operations, the code improperly uses the PicoDB library to update/insert new information. Version 1.2.31 contains a fix for this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:kanboard:kanboard:*:*:*:*:*:*:*:*
Версия до 1.2.31 (исключая)

EPSS

Процентиль: 16%
0.00051
Низкий

7.1 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-89
CWE-89

Связанные уязвимости

CVSS3: 7.1
debian
больше 2 лет назад

Kanboard is project management software that focuses on the Kanban met ...

EPSS

Процентиль: 16%
0.00051
Низкий

7.1 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-89
CWE-89