Privilege Escalation: Unauthorized Editing of Private Project Metadata in Kanboard

Privilege Escalation: Unauthorized Editing of Private Project Metadata in Kanboard

CVE-2017-15199 · MEDIUM Severity

AV:N/AC:L/AU:S/C:N/I:P/A:N

In Kanboard before 1.0.47, by altering form data, an authenticated user can edit metadata of a private project of another user, as demonstrated by Name, Email, Identifier, and Description.

Learn more about our User Device Pen Test.