{"id":"GHSA-3hfj-qcvj-4hx8","aliases":[],"url":"https://o3.security/vulnerability/GHSA-3hfj-qcvj-4hx8","summary":"Leantime has Missing Authorization Check for Host Parameter","details":"### Finding Description\nApplication has functionality for a user to view profile information. It does not have an implemented authorization check for \"Host\" parameter which allows a user to view profile information of another user by replacing \"Host\" parameter.\n\n### Impact\nBy exploiting this vulnerability an attacker can able to view profile information (but not anything else or change anything)","published":"2025-02-21T23:53:22Z","modified":"2025-02-22T00:15:43.483074Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"leantime/leantime","fixedVersion":"3.3"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/Leantime/leantime/security/advisories/GHSA-3hfj-qcvj-4hx8"},{"type":"PACKAGE","url":"https://github.com/Leantime/leantime"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-02-22T00:15:43.483074Z"}}