Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92xh-6x7v-4rmq

Опубликовано: 21 фев. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.9

Описание

Leantime allows Cross-Site Request Forgery (CSRF)

CSRF

Summary

A cross-site request forgery vulnerability allows a remote actor to create an account with Owner privileges. By luring an Owner or Administrator into clicking a button on an attacker-controlled website, a request will be issued, generating an account with the attacker's information and role of their choosing.

Impact

While the likelihood of a successful exploit is low, the impact would be high as the attacker could then gain complete control over the victim's environment.

Пакеты

Наименование

leantime/leantime

composer
Затронутые версииВерсия исправления

< 3.1.2

3.1.2

5.9 Medium

CVSS4

Дефекты

CWE-352

5.9 Medium

CVSS4

Дефекты

CWE-352