CVE-2024-51748
CVSS 3.1 Score 9.1 of 10 (high)
Details
Summary
CVE-2024-51748 is a vulnerability affecting Kanboard, a project management software that utilizes the Kanban methodology. A authenticated admin user can exploit this issue to run arbitrary PHP code on the server, thanks to a file write possibility and a path traversal vulnerability. The attacker must first upload a malicious file named "translations.php" to the system. Once uploaded, the attacker can craft a SQLite database file with a manipulated path, enabling code execution after importing the database. This issue has been resolved in version 1.2.42, and all users are advised to upgrade as soon as possible. There are currently no known workarounds for this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Kanboard
Affected Vendors
- Kanboard