CVE-2026-10285

A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers/KanbanScrumHelper.php of the component Ticket Handler. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.
Configurations

No configuration.

History

01 Jun 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 21:16

Updated : 2026-06-02 13:03


NVD link : CVE-2026-10285

Mitre link : CVE-2026-10285

CVE.ORG link : CVE-2026-10285


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment

CWE-285

Improper Authorization