Leantime是Leantime公司开源的一个面向非项目经理的以目标为中心的项目管理系统。 Leantime 3.6.2之前版本存在服务端请求伪造漏洞,该漏洞源于在Blueprints::import()方法中未对用户提供的文件名进行路径验证直接传递给file_get_contents(),导致服务器端请求伪造和本地文件包含,攻击者可通过JSON-RPC API端点提交特制的包含URL包装器或路径遍历序列的文件名,读取内部资源。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-66416 | 8.8 HIGH | Leantime CSRF Protection Globally Disabled by Omission of Laravel VerifyCsrfToken Middlewa |
| CVE-2026-66414 | 6.1 MEDIUM | Leantime Open Redirect in Login Controller via redirectUrl Parameter |
No comments yet