Back to Database
Status published
Medium
CVE-2017-15198
In Kanboard before 1.0.47, by altering form data, an authenticated...
Vulnerability Description
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit a category of a private project of another user.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-15198
Credits & Attribution
No credits recorded in the NVD database.
References
More from kanboard
View All →CVE-2025-55011
Kanboard Path Traversal in File Write via Task File Upload Api
Medium
6.4
CVE-2025-55010
Kanboard Authenticated Admin Remote Code Execution via Unsafe Deserialization of Events
Critical
9.1
CVE-2025-52576
Kanboard vulnerable to Username Enumeration via Login Behavior and Bruteforce Protection Bypass
Medium
5.3
CVE-2025-52560
Kanboard Password Reset Poisoning via Host Header Injection
High
8.1
CVE-2025-46825
Kanboard has stored Cross-site Scripting vulnerability in project name
Low
1.3
Affected Vendor
kanboard
View all reports →Affected Software
kanboard
Vulnerable Versions:
1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10, 1.0.11, 1.0.12, 1.0.13, 1.0.14, 1.0.15, 1.0.16, 1.0.17, 1.0.18, 1.0.19, 1.0.20, 1.0.21, 1.0.22, 1.0.23, 1.0.24, 1.0.25, 1.0.26, 1.0.27, 1.0.28, 1.0.29, 1.0.30, 1.0.31, 1.0.32, 1.0.33, 1.0.34, 1.0.35, 1.0.36, 1.0.37, 1.0.38, 1.0.39, 1.0.40, 1.0.41, 1.0.42, 1.0.43, 1.0.44, 1.0.45, 1.0.46
Timeline
Official Publish:
October 10th, 2017
Last Modified:
September 16th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.