Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQL injection vulnerability. Attackers with the permission to add users to a project can leverage this vulnerability to dump the entirety of the kanboard database.
Version 1.2.51 fixes the issue.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Kanboard Kanboard
cpe:2.3:a:kanboard:kanboard:*:*:*:*:*:*:*:*
|
— |
1.2.51
|