Количество 2
Количество 2
CVE-2021-39198
OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross-Site Request Forgery (CSRF) attack. There are no workarounds that address this vulnerability and all users are advised to update their package.
GHSA-vf7h-6246-hm43
The disqualify lead action may be executed without CSRF token check
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-39198 OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross-Site Request Forgery (CSRF) attack. There are no workarounds that address this vulnerability and all users are advised to update their package. | CVSS3: 4.2 | 0% Низкий | около 4 лет назад | |
GHSA-vf7h-6246-hm43 The disqualify lead action may be executed without CSRF token check | CVSS3: 4.2 | 0% Низкий | около 4 лет назад |
Уязвимостей на страницу