CVE-2017-12851

Severity CVSS v4.0:
Pending analysis
Type:
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Publication date:
14/08/2017
Last modified:
20/04/2025

Description

An authenticated standard user could reset the password of the admin by altering form data. Affects kanboard before 1.0.46.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kanboard:kanboard:*:*:*:*:*:*:*:* 1.0.45 (including)