JordanKnott/taskcafe

JordanKnott/taskcafe

Releases10
Frequency1 month 1 week
Last Release
Stars5.2K
An open source project management tool with Kanban boards

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can change the password of that user.

6.5 MEDIUM

Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the filetype when uploading a SVG profile picture with a XSS payload on it. An authenticated attacker can exploit this vulnerability by uploading a malicious picture which will trigger the payload when the victim opens the file.

7.5 HIGH5 MEDIUM

Cross domain policies in Taskcafe Project Management tool before version 0.1.0 and 0.1.1 allows remote attackers to access sensitive data such as access token.