VYPR
Unrated severityNVD Advisory· Published Dec 23, 2025· Updated Mar 5, 2026

Orangescrum 1.8.0 Authenticated Privilege Escalation via User Session Manipulation

CVE-2021-47721

Description

Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attackers can extract the victim's unique ID from the page source and replace their own session cookie to gain unauthorized access to another user's account.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.