Description
A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affects some unknown processing of the file /clients/save_contact of the component Contact Information Update. Such manipulation of the argument contact_id leads to authorization bypass. The attack can be launched remotely. The exploit is publicly available and might be used.
Published: 2026-08-17
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in CodeCanyon TimeCamp Integration for CRM allows an attacker to manipulate the contact_id argument of the /clients/save_contact endpoint, leading to an authorization bypass as defined by CWE‑285 and a privilege escalation scenario (CWE‑639). The vulnerability can be triggered remotely, and authenticated or unauthenticated users could exploit it to modify or retrieve contact information they should not have access to. The CVSS score of 5.3 indicates a moderate overall risk due to the lack of a requirement for local privileges but a known remote attack vector.

Affected Systems

The issue affects the TimeCamp Integration for CRM plugin distributed via CodeCanyon. Versions up to and including 2.8 are vulnerable; any installation of the plugin before the definition of the fix in later releases is potentially impacted.

Risk and Exploitability

Because the vulnerability is exploitable over the network and an exploit has been published publicly, the likelihood of attack is non‑negligible even though the EPSS metric is not available. The lack of inclusion in CISA KEV suggests it has not yet been confirmed as widely exploited, but the combination of a remote trigger and moderate CVSS score means that organizations should consider it a real threat.

Generated by OpenCVE AI on August 17, 2026 at 01:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the TimeCamp Integration for CRM component to a version newer than 2.8 or apply the vendor‑supplied patch.
  • If no patch is available, restrict remote access to the /clients/save_contact endpoint, enforcing strict role‑based authentication and limiting exposure to trusted networks only.
  • Monitor the API logs for anomalous contact_id values and investigate any unauthorized modifications.

Generated by OpenCVE AI on August 17, 2026 at 01:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affects some unknown processing of the file /clients/save_contact of the component Contact Information Update. Such manipulation of the argument contact_id leads to authorization bypass. The attack can be launched remotely. The exploit is publicly available and might be used.
Title CodeCanyon TimeCamp Integration for CRM Contact Information Update save_contact authorization
First Time appeared Codecanyon
Codecanyon timecamp Integration For Crm
Weaknesses CWE-285
CWE-639
CPEs cpe:2.3:a:codecanyon:timecamp_integration_for_crm:*:*:*:*:*:*:*:*
Vendors & Products Codecanyon
Codecanyon timecamp Integration For Crm
References
Metrics cvssV2_0

{'score': 5.5, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Codecanyon Timecamp Integration For Crm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-17T00:15:09.037Z

Reserved: 2026-08-16T07:32:53.742Z

Link: CVE-2026-19966

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T01:16:44.200

Modified: 2026-08-17T01:16:44.200

Link: CVE-2026-19966

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T01:30:17Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-639

    Authorization Bypass Through User-Controlled Key