CVE-2024-27474

Leantime 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF). This vulnerability allows malicious actors to perform unauthorized actions on behalf of authenticated users, specifically administrators.
Configurations

No configuration.

History

21 Nov 2024, 09:04

Type Values Removed Values Added
References () https://drive.proton.me/urls/67VER05Z84#f0fXnmp8o6Y9 - () https://drive.proton.me/urls/67VER05Z84#f0fXnmp8o6Y9 -
References () https://github.com/Leantime/leantime/blob/264a7dbc2c9b18f574821bf27dd568a287ee8498/app/Domain/Users/Controllers/NewUser.php#L16 - () https://github.com/Leantime/leantime/blob/264a7dbc2c9b18f574821bf27dd568a287ee8498/app/Domain/Users/Controllers/NewUser.php#L16 -
References () https://github.com/dead1nfluence/Leantime-POC/blob/main/README.md - () https://github.com/dead1nfluence/Leantime-POC/blob/main/README.md -

21 Aug 2024, 21:35

Type Values Removed Values Added
Summary
  • (es) Leantime 3.0.6 es vulnerable a Cross-Site Request Forgery (CSRF). Esta vulnerabilidad permite a actores malintencionados realizar acciones no autorizadas en nombre de usuarios autenticados, específicamente administradores.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-352

10 Apr 2024, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-10 15:16

Updated : 2024-11-21 09:04


NVD link : CVE-2024-27474

Mitre link : CVE-2024-27474

CVE.ORG link : CVE-2024-27474


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)