Tag
high
advisory
Leantime Authenticated LFI and SSRF via Blueprints
1 TTP 1 CVELeantime 3.6.2 contains a vulnerability in the Blueprints::import method allowing authenticated attackers to perform SSRF and LFI via the JSON-RPC API.
Leantime
lfi
ssrf
cve-2026-66415
web-vulnerability
csrf
cve-2026-66416
1t
1c
high
advisory
CVE-2026-59713: Leantime OIDC Login CSRF leading to Session Fixation
3 TTPs 1 CVECVE-2026-59713 identifies a high-severity OIDC login Cross-Site Request Forgery (CSRF) vulnerability in Leantime's verifyState() method, allowing attackers to craft malicious callback URLs with attacker-controlled authorization codes to perform session fixation and log victims into an attacker's session.
Leantime
csrf
oidc
session-fixation
web-application
vulnerability
3t
1c