CVE-2023-45826 is an authenticated SQL injection vulnerability affecting Leantime, an open-source project management system, specifically versions prior to 2.4-beta-4. An authenticated attacker can exploit a non-parameterized 'userId' variable in the application's file repository to dump sensitive information from the database. Rated 6.5 MEDIUM (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N), this vulnerability requires low privileges and has high confidentiality impact. While there is no evidence of active exploitation, a Nuclei template exists, and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4CPE matchmatch criteria | cpe:2.3:a:leantime:leantime:*:*:*:*:*:*:*:* | ||
2.4CPE matchmatch criteria | cpe:2.3:a:leantime:leantime:2.4:-:*:*:*:*:*:* | ||
2.4CPE matchmatch criteria | cpe:2.3:a:leantime:leantime:2.4:beta:*:*:*:*:*:* | ||
2.4CPE matchmatch criteria | cpe:2.3:a:leantime:leantime:2.4:beta2:*:*:*:*:*:* | ||
2.4CPE matchmatch criteria | cpe:2.3:a:leantime:leantime:2.4:beta3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.