8.8
CVSSv3

CVE-2020-26516

Published: 08/06/2021 Updated: 18/10/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A CSRF issue exists in Intland codeBeamer ALM 10.x up to and including 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entirely predicted allowing malicious users to cause the victim's browser to execute undesired actions in the web application through crafted requests.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

intland codebeamer 10.1.0

intland codebeamer 10.0.0

intland codebeamer 10.0.1

intland codebeamer 21.04