CVE-2024-51748

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Nov 11, 2024
Updated: Nov 12, 2024
CWE ID 22

Summary

CVE-2024-51748 is a vulnerability affecting Kanboard, a project management software that utilizes the Kanban methodology. A authenticated admin user can exploit this issue to run arbitrary PHP code on the server, thanks to a file write possibility and a path traversal vulnerability. The attacker must first upload a malicious file named "translations.php" to the system. Once uploaded, the attacker can craft a SQLite database file with a manipulated path, enabling code execution after importing the database. This issue has been resolved in version 1.2.42, and all users are advised to upgrade as soon as possible. There are currently no known workarounds for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share