Kanboard Security Update Advisory

Overview
 

We have released a security update to address a vulnerability in Kanboard. we encourage affected product users to update to the latest version.

 

Affected Products

 

Cve-2024-51747, cve-2024-51748

  • Kanboard version: 1.2.41

 

Resolved Vulnerabilities

 

Vulnerability that allows a user with administrator privileges to upload a maliciously modified sqlite.db to read or delete arbitrary files (CVE-2024-51747)

Vulnerability that could allow a user with administrator privileges to upload a maliciously modified sqlite.db to execute arbitrary PHP code (CVE-2024-51748)

 

 

Vulnerability Patches

vulnerability patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

Cve-2024-51747, cve-2024-51748

  • Kanboard version: 1.2.42

 

 

references

 

[1] CVE-2024-51747 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-51747

[2] Arbitrary File Read and Delete

https://github.com/kanboard/kanboard/security/advisories/GHSA-78pf-vg56-5p8v

[3] CVE-2024-51748 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-51748

[4] Remote code execution through language setting

https://github.com/kanboard/kanboard/security/advisories/GHSA-jvff-x577-j95p