Kanboard是一套开源的可视化任务板软件。该软件能够根据业务定制面板。 Kanboard 1.2.30之前版本存在安全漏洞,该漏洞源于存在访问控制缺失漏洞,允许低权限用户创建任务或将任务转移到软件内的任何项目。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-33969 | 6.4 MEDIUM | Stored Cross site scripting in the Task External Link Functionality in Kanboard |
| CVE-2023-33970 | 5.4 MEDIUM | Missing access control in internal task links feature in Kanboard |
| CVE-2023-33956 | 4.3 MEDIUM | Parameter based Indirect Object Referencing leading to private file exposure in Kanboard |
No comments yet