Description
A vulnerability was found in Lagom WHMCS Template up to 2.3.7. Impacted is an unknown function of the component Datatables. The manipulation results in improperly controlled modification of object prototype attributes. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-03-16
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Prototype Pollution
Action: Patch
AI Analysis

Impact

A vulnerability was identified in the Lagom WHMCS Template version 2.3.7 and earlier, affecting the component that implements Datatables. By manipulating certain user inputs, an attacker can cause the application to alter JavaScript object prototype properties, a flaw known as prototype pollution. This vulnerability can be triggered remotely and an exploit is publicly available, enabling an adversary to potentially modify application logic or inject malicious data.

Affected Systems

The affected product is Lagom WHMCS Template and all releases up to version 2.3.7 are impacted. Any deployment of these versions that utilizes the Datatables portion of the template is at risk because the vulnerability resides in the Datatables handling code.

Risk and Exploitability

The CVSS score for the issue is 5.1, indicating medium severity. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog. However, the public nature of the exploit and the remote attack vector increase the likelihood of real‑world exploitation. Organizations using the affected template should treat this as a moderate risk and act promptly to remediate.

Generated by OpenCVE AI on March 17, 2026 at 12:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Lagom's official website or repository for an updated WHMCS Template that fixes the prototype pollution issue.
  • If a newer version is available, upgrade your template installation to that version immediately.
  • If no update is released, disable or remove the Datatables component from the template to eliminate the vulnerable code path.
  • If disabling Datatables is not possible, add strict input sanitization or validation to restrict data that can affect prototype properties.
  • Monitor application logs and user activity for signs of exploitation and apply any additional hardening measures.

Generated by OpenCVE AI on March 17, 2026 at 12:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 17 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Lagom
Lagom whmcs Template
Vendors & Products Lagom
Lagom whmcs Template

Mon, 16 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Mar 2026 13:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Lagom WHMCS Template up to 2.3.7. Impacted is an unknown function of the component Datatables. The manipulation results in improperly controlled modification of object prototype attributes. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Lagom WHMCS Template Datatables prototype pollution
Weaknesses CWE-1321
CWE-94
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Lagom Whmcs Template
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-16T14:42:22.402Z

Reserved: 2026-03-15T20:37:03.899Z

Link: CVE-2026-4239

cve-icon Vulnrichment

Updated: 2026-03-16T14:42:19.236Z

cve-icon NVD

Status : Deferred

Published: 2026-03-16T14:20:18.703

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-4239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-24T10:44:32Z

Weaknesses