S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 15, 2026

CVE-2023-33960 Scanner

CVE-2023-33960 Scanner - Information Disclosure vulnerability in OpenProject

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-33960
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

OpenProject is web-based project management software. For any OpenProject installation, a `robots.txt` file is generated through the server to denote which routes shall or shall not be accessed by crawlers. These routes contain project identifiers of all public projects in the instance. Prior to version 12.5.6, even if the entire instance is marked as `Login required` and prevents all truly anonymous access, the `/robots.txt` route remains publicly available. Version 12.5.6 has a fix for this issue. Alternatively, users can download a patchfile to apply the patch to any OpenProject version greater than 10.0 As a workaround, one may mark any public project as non-public and give anyone in need of access to the project a membership.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
openprojectby opf
< 12.5.6
Updated Aug 22, 2026View on NVD →
Detail

OpenProject is an open-source project management software used by organizations worldwide to manage their projects efficiently. It is commonly implemented in sectors such as IT, construction, and engineering to plan, communicate, and collaborate on projects. The software offers features like task management, scheduling, and team collaboration, making it essential for structured project execution. OpenProject provides transparency and improved workflows by integrating various assets and documentation into one platform. Organizations also use OpenProject to allocate resources, track time, and report progress, ensuring a comprehensive project overview. This versatile tool aids in organizational productivity by aligning team efforts toward common objectives.

Information Disclosure is a vulnerability where sensitive information is unintentionally exposed to unauthorized users. In the context of OpenProject, this vulnerability allows attackers to access project identifiers through the robots.txt file. Although it might appear harmless, the exposure of project identifiers can lead to targeted attacks or facilitate information gathering by malicious entities. The presence of such a vulnerability compromises the confidentiality of project details, weakening the security posture of the affected instance. Detecting and mitigating such vulnerabilities is vital to ensure that sensitive data is only accessible to authorized individuals. Information Disclosure vulnerabilities often arise from improper access controls or configurations.

Technical details of this Information Disclosure vulnerability in OpenProject indicate that the robots.txt file, which is supposed to limit search engine indexing, contains project identifiers. These identifiers can be accessed without authentication, even if the system requires a login for other activities. The file discloses sensitive paths related to projects, work packages, repositories, and activities. Ensuring such details are not publicly exposed is crucial in fostering a secure environment. The vulnerability primarily affects versions earlier than 12.5.4, which did not have the necessary restrictions in place. The resolution involves updating to the latest version or applying patches that secure the file from unauthorized access.

If exploited, the Information Disclosure vulnerability in OpenProject can lead to several undesirable effects. Attackers can collect project identifiers and other sensitive data, which can support social engineering or targeted cyber attacks. Organizations may face the risk of unauthorized access to project information, posing threats to data integrity and confidentiality. The exposure might give adversaries insights into the structure and operations of an organization, potentially leading to further exploitation. Additionally, the organization's reputation could suffer due to the perceived lack of security controls. Firms affected by such vulnerabilities might also incur financial losses due to potential breaches and legal liabilities.

REFERENCES

Solution Advice
  • Upgrade to OpenProject version 12.5.6 or later to mitigate the risk.
  • Apply the available patch to versions above 10.0 to secure the application.
  • Conduct regular audits to ensure that sensitive files are properly secured and not publicly accessible.
  • Implement strict access controls to limit unauthorized access to sensitive project data.
  • Monitor and review logs to detect any suspicious activity related to the robots.txt file access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-33960 Scanner - Information Disclosure vulnerability in OpenProject | S4E