Impact
The vulnerability resides in the KanbanScrumHelper::recordUpdated function within the Ticket Handler component of DevaslanPHP project-management. A remote attacker can manipulate the update process to bypass authorization checks, enabling unauthorized changes to ticket records. The resulting breach of data integrity can compromise the accuracy and reliability of the ticketing system, as the weakness maps to CWE-266 and CWE-285.
Affected Systems
All installations of the DevaslanPHP project-management component up to and including version 2.0.0-beta1 are affected. The project is maintained on GitHub and no official patch has been released to address the improper authorization flaw.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability is classified as medium severity. The EPSS score is unavailable, and the issue is not listed in the CISA KEV catalog, indicating lower publicized exploitation risk. The attack vector is remote, meaning that a threat actor could exploit the flaw over the network against users who can reach the Ticket Handler endpoints, especially if no additional access control safeguards are in place.
OpenCVE Enrichment