Description
A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers/KanbanScrumHelper.php of the component Ticket Handler. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.
Problem types
Incorrect Privilege Assignment
Product status
Timeline
| 2026-05-31: | Advisory disclosed |
| 2026-05-31: | VulDB entry created |
| 2026-05-31: | VulDB entry last update |
Credits
Mitchell_45 (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/367578 (VDB-367578 | DevaslanPHP project-management Ticket KanbanScrumHelper.php recordUpdated improper authorization)
vuldb.com/vuln/367578/cti (VDB-367578 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-10285 (CVE-2026-10285 | CVE Analysis and Report)
vuldb.com/submit/825475 (Submit #825475 | devaslanphp project-management < 2.0.0-beta1 Improper Authorization)
github.com/devaslanphp/project-management/issues/141
github.com/devaslanphp/project-management/