In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tags of a private project of another user.
CVE Status: Modified
No CVSS data available
Exploit-db Github