OpenProject是OpenProject组织开源的一个基于Web的项目管理软件。 OpenProject 17.6.0之前版本存在授权问题漏洞,该漏洞源于PATCH /api/v3/work_packages/{id}接口接受_links.fileLinks参数,允许具有edit_work_packages权限但无manage_file_links权限的认证用户通过原始ID解析Storages::FileLink记录,分离或硬删除现有FileLink,并将其他项目的FileLink重新挂载至攻击者控
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| opf | openproject | < 17.6.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| opf | openproject | < 17.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67528 | 4.3 MEDIUM | OpenProject: Improper Access Control through /api/v3/custom_options/:id via Path "id" lead |
| CVE-2026-67529 | 4.3 MEDIUM | OpenProject: Private work package subject/identity disclosure through the global Time Entr |
No comments yet