漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Kanboard TaskCreationController::duplicateProjects() endpoint does not validate user permissions for target projects
Vulnerability Description
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is incomplete. The TaskCreationController::duplicateProjects() endpoint does not validate user permissions for target projects, allowing authenticated users to duplicate tasks into projects they cannot access. This vulnerability is fixed in 1.2.50.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
Kanboard 安全漏洞
Vulnerability Description
Kanboard是Kanboard开源的一套开源的可视化任务板软件。该软件能够根据业务定制面板。 Kanboard 1.2.50之前版本存在安全漏洞,该漏洞源于TaskCreationController::duplicateProjects端点未验证用户对目标项目的权限,可能导致经过身份验证的用户将任务复制到其无法访问的项目中。
CVSS Information
N/A
Vulnerability Type
N/A