Improper Authorization Vulnerability in DevaslanPHP Project Management Software
CVE-2026-10285
5.3MEDIUM
What is CVE-2026-10285?
A vulnerability in the DevaslanPHP project management application affects the KanbanScrumHelper::recordUpdated function located in app/Helpers/KanbanScrumHelper.php. This issue allows unauthorized users to perform actions that should be restricted, enabling potential exploitation through remote means. Despite being reported to the project maintainers, there has been no response, leaving users exposed to the risks associated with this flaw. It is critical for administrators to take precautionary measures and update to the latest version to mitigate the risks.
Affected Version(s)
project-management 2.0.0-beta1
