Security Advisory

CVE-2021-47721

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-23 19:34:06
Last updated 2026-03-05 12:02:23
Assigner VulnCheck
State PUBLISHED

Description

Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attackers can extract the victims unique ID from the page source and replace their own session cookie to gain unauthorized access to another users account.