{"id":"GHSA-92xh-6x7v-4rmq","aliases":[],"url":"https://o3.security/vulnerability/GHSA-92xh-6x7v-4rmq","summary":"Leantime allows Cross-Site Request Forgery (CSRF)","details":"**CSRF**\n### Summary\nA cross-site request forgery vulnerability allows a remote actor to create an account with Owner privileges. By luring an Owner or Administrator into clicking a button on an attacker-controlled website, a request will be issued, generating an account with the attacker's information and role of their choosing. \n\n### Impact\nWhile the likelihood of a successful exploit is low, the impact would be high as the attacker could then gain complete control over the victim's environment.","published":"2025-02-21T22:48:41Z","modified":"2025-02-21T23:11:51.954583Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"leantime/leantime","fixedVersion":"3.1.2"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/Leantime/leantime/security/advisories/GHSA-92xh-6x7v-4rmq"},{"type":"PACKAGE","url":"https://github.com/Leantime/leantime"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-02-21T23:11:51.954583Z"}}