CVE-2024-27474

Leantime 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF). This vulnerability allows malicious actors to perform unauthorized actions on behalf of authenticated users, specifically administrators.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:leantime:leantime:3.0.6:*:*:*:*:*:*:*

History

08 Apr 2025, 15:22

Type Values Removed Values Added
CPE cpe:2.3:a:leantime:leantime:3.0.6:*:*:*:*:*:*:*
First Time Leantime
Leantime leantime
References () https://github.com/dead1nfluence/Leantime-POC/blob/main/README.md - () https://github.com/dead1nfluence/Leantime-POC/blob/main/README.md - Exploit, Third Party Advisory
References () https://drive.proton.me/urls/67VER05Z84#f0fXnmp8o6Y9 - () https://drive.proton.me/urls/67VER05Z84#f0fXnmp8o6Y9 - Broken Link
References () https://github.com/Leantime/leantime/blob/264a7dbc2c9b18f574821bf27dd568a287ee8498/app/Domain/Users/Controllers/NewUser.php#L16 - () https://github.com/Leantime/leantime/blob/264a7dbc2c9b18f574821bf27dd568a287ee8498/app/Domain/Users/Controllers/NewUser.php#L16 - Product

10 Apr 2024, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-10 15:16

Updated : 2025-04-08 15:22


NVD link : CVE-2024-27474

Mitre link : CVE-2024-27474


JSON object : View

Products Affected

leantime

  • leantime
CWE

No CWE.