PT-2026-73181 · Codecanyon · Timecamp Integration For Crm

·

CVE-2026-19966

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions CodeCanyon TimeCamp Integration for CRM versions prior to 2.9
Description An authorization bypass exists in the Contact Information Update component due to improper processing of the /clients/save contact endpoint. A remote attacker can exploit this by manipulating the contact id argument.
Recommendations Update CodeCanyon TimeCamp Integration for CRM to version 2.9 or later. As a temporary mitigation, restrict access to the /clients/save contact endpoint.

Exploit

Fix

Improper Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19966

Affected Products

Timecamp Integration For Crm