Back to overview

CVE-2026-10285

MEDIUM
5.4
CVSS 3.1
Description
A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers/KanbanScrumHelper.php of the component Ticket Handler. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.

Metadata

CVE ID
CVE-2026-10285
State
PUBLISHED
Assigner
VulDB
Reserved
2026-05-31 16:30 UTC
Published
2026-06-01 19:15 UTC
Last updated
2026-06-02 12:22 UTC
Primary CWE
CWE-285
Improper Authorization
Vendor / Product
DevaslanPHP / project-management
Sources
cve.org  ·  NVD

Severity & Metrics

5.4 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:X/RC:R
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
DevaslanPHP project-management 2.0.0-beta1
Weakness (CWE)
CWESourceDescription
CWE-266 cna Incorrect Privilege Assignment
CWE-285 cna Improper Authorization
CVSS scores (4)
ScoreSeverityVersionSourceVector
5.5 N/D 2.0 cna AV:N/AC:L/Au:S/C:N/I:P/A:P/E:ND/RL:ND/RC:UR
5.4 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:X/RC:R
5.4 MEDIUM 3.0 cna CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:X/RC:R
5.3 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
References (6)
Back to overview