Description
Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL parameter project_id. If the user is authorized to add users to this project the request gets processed. The users permission for the POST BODY parameter project_id does not get checked again while processing. An attacker with the 'Project Manager' on a single project may take over any other project. The vulnerability is fixed in 1.2.37.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-36061 | Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL parameter project_id. If the user is authorized to add users to this project the request gets processed. The users permission for the POST BODY parameter project_id does not get checked again while processing. An attacker with the 'Project Manager' on a single project may take over any other project. The vulnerability is fixed in 1.2.37. |
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 24 Sep 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kanboard
Kanboard kanboard |
|
| CPEs | cpe:2.3:a:kanboard:kanboard:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kanboard
Kanboard kanboard |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T03:37:05.195Z
Reserved: 2024-05-27T15:59:57.030Z
Link: CVE-2024-36399
Updated: 2024-08-02T03:37:05.195Z
Status : Modified
Published: 2024-06-06T16:15:12.573
Modified: 2024-11-21T09:22:06.037
Link: CVE-2024-36399
No data.
OpenCVE Enrichment
No data.
EUVD