CVE-2023-33970
- EPSS 0.21%
- Veröffentlicht 05.06.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:06:19
Kanboard is open source project management software that focuses on the Kanban methodology. A vulnerability related to a `missing access control` was found, which allows a User with the lowest privileges to leak all the tasks and projects titles with...
CVE-2023-33969
- EPSS 0.09%
- Veröffentlicht 05.06.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:06:19
Kanboard is open source project management software that focuses on the Kanban methodology. A stored Cross site scripting (XSS) allows an attacker to execute arbitrary Javascript and any user who views the task containing the malicious code will be e...
CVE-2023-33968
- EPSS 0.12%
- Veröffentlicht 05.06.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:06:18
Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are subject to a missing access control vulnerability that allows a user with low privileges to create or transfer tasks to any proje...
CVE-2023-32685
- EPSS 0.66%
- Veröffentlicht 30.05.2023 05:15:11
- Zuletzt bearbeitet 21.11.2024 08:03:50
Kanboard is project management software that focuses on the Kanban methodology. Due to improper handling of elements under the `contentEditable` element, maliciously crafted clipboard content can inject arbitrary HTML tags into the DOM. A low-privile...
CVE-2019-7324
- EPSS 0.29%
- Veröffentlicht 04.02.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:48:00
app/Core/Paginator.php in Kanboard before 1.2.8 has XSS in pagination sorting.
CVE-2017-15212
- EPSS 0.33%
- Veröffentlicht 11.10.2017 01:32:55
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Kanboard before 1.0.47, by altering form data, an authenticated user can at least see the names of tags of a private project of another user.
CVE-2017-15211
- EPSS 0.54%
- Veröffentlicht 11.10.2017 01:32:55
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Kanboard before 1.0.47, by altering form data, an authenticated user can add an external link to a private project of another user.
CVE-2017-15210
- EPSS 0.29%
- Veröffentlicht 11.10.2017 01:32:55
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Kanboard before 1.0.47, by altering form data, an authenticated user can see thumbnails of pictures from a private project of another user.
CVE-2017-15209
- EPSS 0.47%
- Veröffentlicht 11.10.2017 01:32:55
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove attachments from a private project of another user.
CVE-2017-15208
- EPSS 0.54%
- Veröffentlicht 11.10.2017 01:32:55
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove automatic actions from a private project of another user.