Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-36399

Опубликовано: 06 июн. 2024
Источник: nvd
CVSS3: 8.2
CVSS3: 6.3
EPSS Низкий

Описание

Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL parameter project_id. If the user is authorized to add users to this project the request gets processed. The users permission for the POST BODY parameter project_id does not get checked again while processing. An attacker with the 'Project Manager' on a single project may take over any other project. The vulnerability is fixed in 1.2.37.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:kanboard:kanboard:*:*:*:*:*:*:*:*
Версия до 1.2.37 (исключая)

EPSS

Процентиль: 39%
0.00178
Низкий

8.2 High

CVSS3

6.3 Medium

CVSS3

Дефекты

CWE-284
CWE-639

Связанные уязвимости

CVSS3: 8.2
debian
больше 1 года назад

Kanboard is project management software that focuses on the Kanban met ...

EPSS

Процентиль: 39%
0.00178
Низкий

8.2 High

CVSS3

6.3 Medium

CVSS3

Дефекты

CWE-284
CWE-639