Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attackers can extract the victim's unique ID from the page source and replace their own session cookie to gain unauthorized access to another user's account.
History

Tue, 23 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 23 Dec 2025 19:45:00 +0000

Type Values Removed Values Added
Description Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attackers can extract the victim's unique ID from the page source and replace their own session cookie to gain unauthorized access to another user's account.
Title Orangescrum 1.8.0 Authenticated Privilege Escalation via User Session Manipulation
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-23T20:03:15.402Z

Reserved: 2025-12-07T14:12:38.077Z

Link: CVE-2021-47721

cve-icon Vulnrichment

Updated: 2025-12-23T20:03:01.089Z

cve-icon NVD

Status : Received

Published: 2025-12-23T20:15:44.510

Modified: 2025-12-23T20:15:44.510

Link: CVE-2021-47721

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.