cvedb.io
CVE-2023-33956
MEDIUM · CVSS 4.3
EPSS exploitation probability: 0%
Published 2023-06-05T20:15:09.460 · Last modified 2026-06-17T06:02:35.847

Summary

Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are subject to an Insecure direct object reference (IDOR) vulnerability present in the application's URL parameter. This vulnerability enables any user to read files uploaded by any other user, regardless of their privileges or restrictions. By Changing the file_id any user can render all the files where MimeType is image uploaded under **/files** directory regard less of uploaded by any user. This vulnerability poses a significant impact and severity to the application's security. By manipulating the URL parameter, an attacker can access sensitive files that should only be available to authorized users. This includes confidential documents or any other type of file stored w

Affected products

kanboard — kanboard

Does this affect you?

Add your gear to cvedb and we'll alert you only when kanboard ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.