CVE-2021-47721 - Orangescrum 1.8.0 Authenticated Privilege Escalation via User Session Manipulation

CVE-2021-47721 - Orangescrum 1.8.0 Authenticated Privilege Escalation via User Session Manipulation

CVE ID : CVE-2021-47721 Published : Dec. 23, 2025, 8:15 p.m. | 32 minutes ago Description : Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attackers can extract the victim's unique ID from the page source and replace their own session cookie to gain unauthorized access to another user's account. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
Dec. 23, 2025
Impact: privilege escalation

Source: Telegram CVE Monitor