Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7j6f-xmpq-5jjm

Опубликовано: 16 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 7.1

Описание

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary properties including identifier, version, and license key to deploy malicious plugins.

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary properties including identifier, version, and license key to deploy malicious plugins.

7.1 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.1
nvd
1 день назад

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary properties including identifier, version, and license key to deploy malicious plugins.

7.1 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-862