File Download Vulnerability in Kanboard By Kanboard
CVE-2017-15205

4.3MEDIUM

Key Information:

Vendor
Kanboard
Status
Vendor
CVE Published:
3 October 2022

Summary

An authentication flaw in Kanboard prior to version 1.0.47 allows an authenticated user to manipulate form data, enabling them to download attachments from another user's private project. This vulnerability poses serious risks to user data confidentiality, making it essential for users to upgrade to the latest version to safeguard their project information.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2017-15205 : File Download Vulnerability in Kanboard By Kanboard | SecurityVulnerability.io