VYPR

by Kanboard

Source repositories

CVEs (46)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-12851Hig0.578.80.00Aug 14, 2017An authenticated standard user could reset the password of the admin by altering form data. Affects kanboard before 1.0.46.
CVE-2017-12850Hig0.578.80.00Aug 14, 2017An authenticated standard user could reset the password of other users (including the admin) by altering form data. Affects kanboard before 1.0.46.
CVE-2017-15212Med0.284.30.00Oct 11, 2017In Kanboard before 1.0.47, by altering form data, an authenticated user can at least see the names of tags of a private project of another user.
CVE-2017-15211Med0.284.30.01Oct 11, 2017In Kanboard before 1.0.47, by altering form data, an authenticated user can add an external link to a private project of another user.
CVE-2017-15210Med0.284.30.00Oct 11, 2017In Kanboard before 1.0.47, by altering form data, an authenticated user can see thumbnails of pictures from a private project of another user.
CVE-2017-15209Med0.284.30.00Oct 11, 2017In Kanboard before 1.0.47, by altering form data, an authenticated user can remove attachments from a private project of another user.
CVE-2017-15208Med0.284.30.01Oct 11, 2017In Kanboard before 1.0.47, by altering form data, an authenticated user can remove automatic actions from a private project of another user.
CVE-2017-15207Med0.284.30.01Oct 11, 2017In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tasks of a private project of another user.
CVE-2017-15206Med0.284.30.01Oct 11, 2017In Kanboard before 1.0.47, by altering form data, an authenticated user can add an internal link to a private project of another user.
CVE-2017-15205Med0.284.30.00Oct 11, 2017In Kanboard before 1.0.47, by altering form data, an authenticated user can download attachments from a private project of another user.
CVE-2017-15204Med0.284.30.01Oct 11, 2017In Kanboard before 1.0.47, by altering form data, an authenticated user can add automatic actions to a private project of another user.
CVE-2017-15203Med0.284.30.01Oct 11, 2017In Kanboard before 1.0.47, by altering form data, an authenticated user can remove categories from a private project of another user.
CVE-2017-15202Med0.284.30.01Oct 11, 2017In Kanboard before 1.0.47, by altering form data, an authenticated user can edit columns of a private project of another user.
CVE-2017-15201Med0.284.30.00Oct 11, 2017In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tags of a private project of another user.
CVE-2017-15200Med0.284.30.00Oct 11, 2017In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new task to a private project of another user.
CVE-2017-15199Med0.284.30.00Oct 11, 2017In Kanboard before 1.0.47, by altering form data, an authenticated user can edit metadata of a private project of another user, as demonstrated by Name, Email, Identifier, and Description.
CVE-2017-15198Med0.284.30.01Oct 11, 2017In Kanboard before 1.0.47, by altering form data, an authenticated user can edit a category of a private project of another user.
CVE-2017-15197Med0.284.30.00Oct 11, 2017In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new category to a private project of another user.
CVE-2017-15196Med0.284.30.00Oct 11, 2017In Kanboard before 1.0.47, by altering form data, an authenticated user can remove columns from a private project of another user.
CVE-2017-15195Med0.284.30.00Oct 11, 2017In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of another user.