Kanboard Multiple Privilege Escalation Vulnerabilities
BID:100352
CVE-2017-12850 | CVE-2017-12851 |Info
Kanboard Multiple Privilege Escalation Vulnerabilities
| Bugtraq ID: | 100352 |
| Class: | Design Error |
| CVE: |
CVE-2017-12850 CVE-2017-12851 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 15 2017 12:00AM |
| Updated: | Aug 15 2017 12:00AM |
| Credit: | chbi |
| Vulnerable: |
Kanboard Kanboard 1.0.45 |
| Not Vulnerable: |
Kanboard Kanboard 1.0.46 |
Exploit / POC
Kanboard Multiple Privilege Escalation Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Kanboard Multiple Privilege Escalation Vulnerabilities
References:
References:
- Kanboard HomePage (Kanboard)
- Filter variables when updating user profile (Github)
- Make sure only admins can change password of other users (Github)