GHSA-92xh-6x7v-4rmq: Leantime allows Cross-Site Request Forgery (CSRF)
A cross-site request forgery vulnerability allows a remote actor to create an account with Owner privileges. By luring an Owner or Administrator into clicking a button on an attacker-controlled website, a request will be issued, generating an account with the attacker’s information and role of their choosing.
References
Detect and mitigate GHSA-92xh-6x7v-4rmq with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →