NA

CVE-2024-27474

Published: 10/04/2024 Updated: 10/04/2024

Vulnerability Summary

Leantime 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF). This vulnerability allows malicious actors to perform unauthorized actions on behalf of authenticated users, specifically administrators.

Github Repositories

CVE-2024-27474, CVE-2024-27476, CVE-2024-27477

Leantime-POC CVE-2024-27474, CVE-2024-27476, CVE-2024-27477