Kanboard是一套开源的可视化任务板软件。该软件能够根据业务定制面板。 Kanboard 1.2.30之前版本存在跨站脚本漏洞,该漏洞源于存在存储型跨站脚本(XSS),允许攻击者执行任意Javascript。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-33970 | 5.4 MEDIUM | Missing access control in internal task links feature in Kanboard |
| CVE-2023-33968 | 5.4 MEDIUM | Missing Access Control allows User to move and duplicate tasks in Kanboard |
| CVE-2023-33956 | 4.3 MEDIUM | Parameter based Indirect Object Referencing leading to private file exposure in Kanboard |
No comments yet