VDB
Sign up
MEDIUM4.3

GHSA-v4cr-m5f8-gxw8

yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)

Quick fix

GHSA-v4cr-m5f8-gxw8 — yetiforce/yetiforce-crm: upgrade to the fixed version with the command below.

composer require yetiforce/yetiforce-crm:^6.3.0

Details

yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF).

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/yetiforce/yetiforce-crm
Introduced in: 0Fixed in: 6.3.0
Fixcomposer require yetiforce/yetiforce-crm:^6.3.0

References