PT-2026-66545 · Leantime · Leantime
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Leantime version 3.6.2
Description
An issue exists where the Laravel
VerifyCsrfToken middleware is excluded from the global middleware stack in app/Http/Kernel.php. This allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by crafting malicious pages delivered via phishing emails or websites. This can trigger unauthorized POST, PUT, and DELETE requests to create or delete projects, modify settings, and change permissions. Cross-site request forgery is a type of attack that forces an authenticated user to execute unwanted actions on a web application.Recommendations
Update Leantime to a version newer than 3.6.2.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Leantime