Description
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update their entire user document (beyond profile fields), including orgs/teams and loginDisabled, due to missing server-side authorization checks; this enables privilege escalation and unauthorized access to other teams/orgs.
INFO
Published Date :
2025-12-15T00:00:00.000Z
Last Modified :
2025-12-15T14:12:08.407Z
Source :
mitre
AFFECTED PRODUCTS
The following products are affected by CVE-2025-65780 vulnerability.
| Vendors | Products |
|---|---|
| Wekan Project |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-65780.