Learn about CVE-2017-15197, a vulnerability in Kanboard allowing users to manipulate form data and create new categories in private projects. Find mitigation steps here.
In versions prior to 1.0.47 of Kanboard, a registered user can manipulate form data to create a new category within the private project of another user.
Understanding CVE-2017-15197
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new category to a private project of another user.
What is CVE-2017-15197?
This CVE refers to a vulnerability in Kanboard that allows a registered user to manipulate form data and create a new category within another user's private project.
The Impact of CVE-2017-15197
Technical Details of CVE-2017-15197
Vulnerability Description
The vulnerability in Kanboard allows an authenticated user to add a new category to a private project of another user by altering form data.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates