CVE-2026-10285
DevaslanPHP project-management Ticket KanbanScrumHelper.php recordUpdated improper authorization
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 5.3EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
01 jun 2026Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers/KanbanScrumHelper.php of the component Ticket Handler. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
Produtos afetados
DevaslanPHP · project-managementQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →