{"id":"CVE-2021-4092","aliases":["GHSA-v4cr-m5f8-gxw8"],"url":"https://o3.security/vulnerability/CVE-2021-4092","summary":"yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)","details":"yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)","published":"2021-12-11T14:15:07.900Z","modified":"2026-07-08T23:58:21.390459Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"},"epss":{"score":0.00382,"percentile":0.31534,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"yetiforce/yetiforce-crm","fixedVersion":"6.3.0"}],"fix":{"url":"https://github.com/yetiforcecompany/yetiforcecrm/commit/585da04bb72d36a894f6ea5939ab909e53fd8c23","label":"yetiforcecompany/yetiforcecrm@585da04"},"references":[{"type":"FIX","url":"https://github.com/yetiforcecompany/yetiforcecrm/commit/585da04bb72d36a894f6ea5939ab909e53fd8c23"},{"type":"FIX","url":"https://huntr.dev/bounties/7b58c160-bb62-45fe-ad1f-38354378b89e"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T23:58:21.390459Z"}}