File Download Vulnerability in Kanboard By Kanboard
CVE-2017-15205
4.3MEDIUM
Summary
An authentication flaw in Kanboard prior to version 1.0.47 allows an authenticated user to manipulate form data, enabling them to download attachments from another user's private project. This vulnerability poses serious risks to user data confidentiality, making it essential for users to upgrade to the latest version to safeguard their project information.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved