PT-2026-73181 · Codecanyon · Timecamp Integration For Crm
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CodeCanyon TimeCamp Integration for CRM versions prior to 2.9
Description
An authorization bypass exists in the Contact Information Update component due to improper processing of the
/clients/save contact endpoint. A remote attacker can exploit this by manipulating the contact id argument.Recommendations
Update CodeCanyon TimeCamp Integration for CRM to version 2.9 or later.
As a temporary mitigation, restrict access to the
/clients/save contact endpoint.Exploit
Fix
Improper Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Timecamp Integration For Crm