An authenticated standard user could reset the password of other users (including the admin) by altering form data. Affects kanboard prior to 1.0.46.
kanboard kanboard