Description
WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than requiring write permission. This can allow users with read-only roles to perform card updates that should require write access.
Problem types
CWE-863 Incorrect Authorization
Product status
Any version before 8.19
Credits
Joshua Rogers
References
github.com/...ommit/181f837d8cbae96bdf9dcbd31beaa3653c2c0285
wekan.fi/
www.vulncheck.com/...-read-only-board-roles-can-update-cards