Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vwm8-rprj-29f7

Опубликовано: 06 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.1

Описание

Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization codes to perform session fixation, logging victims in as the attacker.

Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization codes to perform session fixation, logging victims in as the attacker.

EPSS

Процентиль: 14%
0.00234
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.1
nvd
около 2 месяцев назад

Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization codes to perform session fixation, logging victims in as the attacker.

EPSS

Процентиль: 14%
0.00234
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-352