Kanboard Security Update Advisory
Overview
We have released a security update to address a vulnerability in Kanboard. we encourage affected product users to update to the latest version.
Affected Products
Cve-2024-51747, cve-2024-51748
- Kanboard version: 1.2.41
Resolved Vulnerabilities
Vulnerability that allows a user with administrator privileges to upload a maliciously modified sqlite.db to read or delete arbitrary files (CVE-2024-51747)
Vulnerability that could allow a user with administrator privileges to upload a maliciously modified sqlite.db to execute arbitrary PHP code (CVE-2024-51748)
Vulnerability Patches
vulnerability patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
Cve-2024-51747, cve-2024-51748
- Kanboard version: 1.2.42
references
[1] CVE-2024-51747 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-51747
[2] Arbitrary File Read and Delete
https://github.com/kanboard/kanboard/security/advisories/GHSA-78pf-vg56-5p8v
[3] CVE-2024-51748 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-51748
[4] Remote code execution through language setting
https://github.com/kanboard/kanboard/security/advisories/GHSA-jvff-x577-j95p