CyberRota Analysis
AI-GeneratedPhproject versions prior to 1.8.7 are vulnerable due to a missing object-level authorization in the REST API, allowing authenticated API key holders to bypass access controls. This vulnerability enables attackers to read sensitive issue contents and comments, including email addresses, and to post unauthorized comments. Organizations using Phproject should prioritize patching this vulnerability to protect sensitive information and maintain the integrity of their issue tracking system.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Phproject before 1.8.7 contains a missing object-level authorization vulnerability in the REST API issue endpoints (single_get, single_comments, single_comments_post) that allows authenticated API key holders to bypass the security.restrict_access confidentiality control by never invoking the allowAccess() authorization routine. Attackers can use a valid API key to read restricted issue contents and comments, including owner and author email addresses, and post unauthorized comments to issues they should not have access to.