Orangescrum Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in Orangescrum version 1.8.0. This vulnerability allows authenticated users to take over accounts of other users assigned to the same project by manipulating session cookies. Exploitation involves extracting the unique ID of the target user from the page source and replacing the attacker's session cookie with it, thereby gaining unauthorized access to the victim's account.

Impact

Exploitation of this vulnerability allows for unauthorized account access, enabling an attacker to assume the identity and privileges of another user within the application.

Reproduction

To reproduce this vulnerability, an authenticated user must be assigned to the same project as the target account. First, access the dashboard and view the page source to locate the 'uniq_id' of the victim account. Once identified, replace the 'USER_UNIQ' cookie with the victim's unique ID. After refreshing the page, access will be granted to the victim's account.

Added: Dec 23, 2025, 8:26 PM
Updated: Dec 23, 2025, 8:26 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
5.0
exploitability
6.6
remediation
0.0
relevance
1.6
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.