Vendor
Phproject versions before 1.8.7 contain a missing object-level authorization vulnerability in REST API issue endpoints that allows authenticated attackers to bypass security restrictions.