Vulnerability Description
Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attackers can extract the victim's unique ID from the page source and replace their own session cookie to gain unauthorized access to another user's account.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Orangescrum | Orangescrum | 1.8.0 |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/50551Exploit
- https://www.orangescrum.org/Product
- https://www.vulncheck.com/advisories/orangescrum-authenticated-privilege-escalatThird Party Advisory
FAQ
What is CVE-2021-47721?
CVE-2021-47721 is a vulnerability with a CVSS score of 8.8 (HIGH). Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attackers can extract the ...
How severe is CVE-2021-47721?
CVE-2021-47721 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-47721?
Check the references section above for vendor advisories and patch information. Affected products include: Orangescrum Orangescrum.