VDB
Sign up
MEDIUM4.2

GHSA-vf7h-6246-hm43

The disqualify lead action may be executed without CSRF token check

Quick fix

GHSA-vf7h-6246-hm43 — oro/crm: upgrade to the fixed version with the command below.

composer require oro/crm:^4.1.17

Details

### Summary The attacker is able to disqualify any Lead with a Cross-Site Request Forgery (CSRF) attack.

### Workarounds There are no workarounds that address this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/oro/crm
Introduced in: 3.1.0Fixed in: 4.1.17
Fixcomposer require oro/crm:^4.1.17
Packagist/oro/crm
Introduced in: 4.2.0Fixed in: 4.2.7
Fixcomposer require oro/crm:^4.2.7

References