Описание
Leantime allows Cross-Site Request Forgery (CSRF)
CSRF
Summary
A cross-site request forgery vulnerability allows a remote actor to create an account with Owner privileges. By luring an Owner or Administrator into clicking a button on an attacker-controlled website, a request will be issued, generating an account with the attacker's information and role of their choosing.
Impact
While the likelihood of a successful exploit is low, the impact would be high as the attacker could then gain complete control over the victim's environment.
Пакеты
Наименование
leantime/leantime
composer
Затронутые версииВерсия исправления
< 3.1.2
3.1.2
5.9 Medium
CVSS4
Дефекты
CWE-352
5.9 Medium
CVSS4
Дефекты
CWE-352