VYPR
High severity8.8NVD Advisory· Published Dec 23, 2025· Updated Jun 17, 2026

CVE-2021-47721

CVE-2021-47721

Description

Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attackers can extract the victim's unique ID from the page source and replace their own session cookie to gain unauthorized access to another user's account.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Orangescrum/Orangescrumllm-fuzzy3 versions
    =1.8.0+ 2 more
    • (no CPE)range: =1.8.0
    • (no CPE)range: 1.8.0
    • cpe:2.3:a:orangescrum:orangescrum:1.8.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.