CVE-2023-36813
published 2023-07-05CVE-2023-36813: Kanboard is project management software that focuses on the Kanban methodology. In versions prior to 1.2.31authenticated user is able to perform a SQL…
PriorityP350high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.92%
56.4th percentile
Kanboard is project management software that focuses on the Kanban methodology. In versions prior to 1.2.31authenticated user is able to perform a SQL Injection, leading to a privilege escalation or loss of confidentiality. It appears that in some insert and update operations, the code improperly uses the PicoDB library to update/insert new information. Version 1.2.31 contains a fix for this issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kanboard | < kanboard 1.2.31+ds-1 (forky) | kanboard 1.2.31+ds-1 (forky) |
| kanboard | kanboard | < 1.2.31 | 1.2.31 |
| kanboard | kanboard | >= 0 < 1.2.31+ds-1 | 1.2.31+ds-1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-36813: Kanboard is project management software that focuses on the Kanban methodology
osv·2023-07-05·CVSS 8.8
CVE-2023-36813 [HIGH] CVE-2023-36813: Kanboard is project management software that focuses on the Kanban methodology
Kanboard is project management software that focuses on the Kanban methodology. In versions prior to 1.2.31authenticated user is able to perform a SQL Injection, leading to a privilege escalation or loss of confidentiality. It appears that in some insert and update operations, the code improperly uses the PicoDB library to update/insert new information. Version 1.2.31 contains a fix for this issue.
Debian
CVE-2023-36813: kanboard - Kanboard is project management software that focuses on the Kanban methodology. ...
vendor_debian·2023·CVSS 7.1
CVE-2023-36813 [HIGH] CVE-2023-36813: kanboard - Kanboard is project management software that focuses on the Kanban methodology. ...
Kanboard is project management software that focuses on the Kanban methodology. In versions prior to 1.2.31authenticated user is able to perform a SQL Injection, leading to a privilege escalation or loss of confidentiality. It appears that in some insert and update operations, the code improperly uses the PicoDB library to update/insert new information. Version 1.2.31 contains a fix for this issue.
Scope: local
forky: resolved (fixed in 1.2.31+ds-1)
sid: resolved (fixed in 1.2.31+ds-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/kanboard/kanboard/commit/25b93343baeaf8ad018dcd87b094e47a5c6a3e0ahttps://github.com/kanboard/kanboard/releases/tag/v1.2.31https://github.com/kanboard/kanboard/security/advisories/GHSA-9gvq-78jp-jxcxhttps://www.debian.org/security/2023/dsa-5454https://github.com/kanboard/kanboard/commit/25b93343baeaf8ad018dcd87b094e47a5c6a3e0ahttps://github.com/kanboard/kanboard/releases/tag/v1.2.31https://github.com/kanboard/kanboard/security/advisories/GHSA-9gvq-78jp-jxcxhttps://www.debian.org/security/2023/dsa-5454
2023-07-05
Published