Unrated severityNVD Advisory· Published Oct 16, 2007· Updated Jun 16, 2026
CVE-2007-5486
CVE-2007-5486
Description
dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this module via a crafted URL. NOTE: some of these details are obtained from third party information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:dotproject:dotproject:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:dotproject:dotproject:*:*:*:*:*:*:*:*range: <=2.0.4
- (no CPE)range: <2.1
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.