Kanboard是一套开源的可视化任务板软件。该软件能够根据业务定制面板。 Kanboard 1.2.29及之前版本存在安全漏洞,该漏洞源于缺少访问控制,允许低权限的用户泄露软件中的所有任务和项目标题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-33969 | 6.4 MEDIUM | Stored Cross site scripting in the Task External Link Functionality in Kanboard |
| CVE-2023-33968 | 5.4 MEDIUM | Missing Access Control allows User to move and duplicate tasks in Kanboard |
| CVE-2023-33956 | 4.3 MEDIUM | Parameter based Indirect Object Referencing leading to private file exposure in Kanboard |
No comments yet