WeKan
cpe:2.3:a:wekan_project:wekan:*:*:*:*:*:*:*
- < 8.19
A vulnerability exists in WeKan versions prior to 8.19, where the attachment upload API fails to properly validate the consistency of provided identifiers, such as boardId, cardId, swimlaneId, and listId. This lack of validation allows for the upload of attachments with mismatched object relationships, creating an authorization weakness.
Exploitation of this vulnerability could lead to incorrect associations between attachments and their respective cards or boards, potentially causing confusion or mismanagement of tasks within the application.
Users can upgrade to WeKan version 8.19 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.