CVE-2014-3920

Cross-site request forgery (CSRF) vulnerability in Kanboard before 1.0.6 allows remote attackers to hijack the authentication of administrators for requests that add an administrative user via a save action to the default URI.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
VendorProductVersion
kanboardkanboard
𝑥
≤ 1.0.6
kanboardkanboard
1.0.0
kanboardkanboard
1.0.1
kanboardkanboard
1.0.2
kanboardkanboard
1.0.3
kanboardkanboard
1.0.4
kanboardkanboard
1.0.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
kanboard
bookworm
1.2.26+ds-2+deb12u2
fixed
bookworm (security)
1.2.26+ds-2+deb12u2
fixed
sid
1.2.31+ds2-1
fixed