Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attackers can extract the victim's unique ID from the page source and replace their own session cookie to gain unauthorized access to another user's account.
References
| Link | Resource |
|---|---|
| https://www.exploit-db.com/exploits/50551 | Exploit |
| https://www.orangescrum.org/ | Product |
| https://www.vulncheck.com/advisories/orangescrum-authenticated-privilege-escalation-via-user-session-manipulation | Third Party Advisory |
Configurations
History
31 Dec 2025, 21:44
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Orangescrum
Orangescrum orangescrum |
|
| CPE | cpe:2.3:a:orangescrum:orangescrum:1.8.0:*:*:*:*:*:*:* | |
| References | () https://www.exploit-db.com/exploits/50551 - Exploit | |
| References | () https://www.orangescrum.org/ - Product | |
| References | () https://www.vulncheck.com/advisories/orangescrum-authenticated-privilege-escalation-via-user-session-manipulation - Third Party Advisory |
23 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-23 20:15
Updated : 2025-12-31 21:44
NVD link : CVE-2021-47721
Mitre link : CVE-2021-47721
CVE.ORG link : CVE-2021-47721
JSON object : View
Products Affected
orangescrum
- orangescrum
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
