Impact
Leantime 3.6.2 lacks the Laravel VerifyCsrfToken middleware in its global middleware stack, creating a cross‑site request forgery flaw that enables attackers to execute POST, PUT, and DELETE actions without authentication. The vulnerability can be exploited to create or delete projects, alter settings, and modify user permissions as any authenticated user, representing a classic example of CWE‑352.
Affected Systems
The flaw affects installations of Leantime version 3.6.2. Any deployment running this version without the missing CSRF protection is exposed.
Risk and Exploitability
With a CVSS score of 8.6 the vulnerability is severe; the EPSS score is than 1% yet the lack of CSRF checks makes exploitation straightforward. Attackers can drive victims to malicious pages via phishing or compromised sites to submit unauthorized requests. The vulnerability is not currently listed in CISA KEV, yet the exposure is large enough that patching should be top priority.
OpenCVE Enrichment