Vulnerabilities > Kanboard > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-10-11 CVE-2017-15200 Authorization Bypass Through User-Controlled Key vulnerability in Kanboard
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new task to a private project of another user.
network
low complexity
kanboard CWE-639
4.0
2017-10-11 CVE-2017-15199 Authorization Bypass Through User-Controlled Key vulnerability in Kanboard
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit metadata of a private project of another user, as demonstrated by Name, Email, Identifier, and Description.
network
low complexity
kanboard CWE-639
4.0
2017-10-11 CVE-2017-15198 Information Exposure vulnerability in Kanboard
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit a category of a private project of another user.
network
low complexity
kanboard CWE-200
4.0
2017-10-11 CVE-2017-15197 Authorization Bypass Through User-Controlled Key vulnerability in Kanboard
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new category to a private project of another user.
network
low complexity
kanboard CWE-639
4.0
2017-10-11 CVE-2017-15196 Authorization Bypass Through User-Controlled Key vulnerability in Kanboard
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove columns from a private project of another user.
network
low complexity
kanboard CWE-639
4.0
2017-10-11 CVE-2017-15195 Authorization Bypass Through User-Controlled Key vulnerability in Kanboard
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of another user.
network
low complexity
kanboard CWE-639
4.0
2017-08-14 CVE-2017-12851 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Kanboard
An authenticated standard user could reset the password of the admin by altering form data.
network
low complexity
kanboard CWE-640
4.0
2017-08-14 CVE-2017-12850 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Kanboard
An authenticated standard user could reset the password of other users (including the admin) by altering form data.
network
low complexity
kanboard CWE-640
4.0
2014-07-03 CVE-2014-3920 Cross-Site Request Forgery (CSRF) vulnerability in Kanboard
Cross-site request forgery (CSRF) vulnerability in Kanboard before 1.0.6 allows remote attackers to hijack the authentication of administrators for requests that add an administrative user via a save action to the default URI.
network
kanboard CWE-352
6.8