CVE-2021-39198
19.11.2021, 22:15
OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross-Site Request Forgery (CSRF) attack. There are no workarounds that address this vulnerability and all users are advised to update their package.
Vendor | Product | Version |
---|---|---|
oroinc | client_relationship_management | 3.1.0 ≤ 𝑥 ≤ 3.1.24 |
oroinc | client_relationship_management | 4.1.0 ≤ 𝑥 ≤ 4.1.15 |
oroinc | client_relationship_management | 4.2.0 ≤ 𝑥 ≤ 4.2.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration