Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Kanboard BoardAjaxController Missing Ownership Check via Drag-and-Drop
Vulnerability Description
Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the attacker-supplied project_id but never verifies that the supplied task_id actually belongs to that project. Because task identifiers are sequential integers shared across the entire instance, any authenticated user who is a member of at least one project can enumerate and move (corrupt/hide) tasks belonging to any other project on the same instance, including private projects they have no membership or role on.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Kanboard 授权问题漏洞
Vulnerability Description
Kanboard是Kanboard团队开源的一套开源的可视化任务板软件。该软件能够根据业务定制面板。 kanboard 1.2.52之前版本存在授权问题漏洞,该漏洞源于BoardAjaxController save()方法在验证调用者角色时未检查任务ID是否属于指定项目,可能导致已通过身份验证的用户枚举和移动(隐藏/破坏)同一实例中其他项目的任务,包括未授权的私有项目。
CVSS Information
N/A
Vulnerability Type
N/A