Vulnerability Description
OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross-Site Request Forgery (CSRF) attack. There are no workarounds that address this vulnerability and all users are advised to update their package.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oroinc | Client Relationship Management | >= 3.1.0, <= 3.1.24 |
Related Weaknesses (CWE)
References
- https://github.com/oroinc/crm/security/advisories/GHSA-vf7h-6246-hm43Third Party Advisory
- https://github.com/oroinc/crm/security/advisories/GHSA-vf7h-6246-hm43Third Party Advisory
FAQ
What is CVE-2021-39198?
CVE-2021-39198 is a vulnerability with a CVSS score of 4.2 (MEDIUM). OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross...
How severe is CVE-2021-39198?
CVE-2021-39198 has been rated MEDIUM with a CVSS base score of 4.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-39198?
Check the references section above for vendor advisories and patch information. Affected products include: Oroinc Client Relationship Management.