Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL parameter project_id. If the user is authorized to add users to this project the request gets processed. The users permission for the POST BODY parameter project_id does not get checked again while processing. An attacker with the 'Project Manager' on a single project may take over any other project. The vulnerability is fixed in 1.2.37.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-36061 Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL parameter project_id. If the user is authorized to add users to this project the request gets processed. The users permission for the POST BODY parameter project_id does not get checked again while processing. An attacker with the 'Project Manager' on a single project may take over any other project. The vulnerability is fixed in 1.2.37.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00118}

epss

{'score': 0.00137}


Tue, 24 Sep 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Kanboard
Kanboard kanboard
CPEs cpe:2.3:a:kanboard:kanboard:*:*:*:*:*:*:*:*
Vendors & Products Kanboard
Kanboard kanboard

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T03:37:05.195Z

Reserved: 2024-05-27T15:59:57.030Z

Link: CVE-2024-36399

cve-icon Vulnrichment

Updated: 2024-08-02T03:37:05.195Z

cve-icon NVD

Status : Modified

Published: 2024-06-06T16:15:12.573

Modified: 2024-11-21T09:22:06.037

Link: CVE-2024-36399

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.