Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization codes to perform session fixation, logging victims in as the attacker.
References
Configurations
No configuration.
History
06 Jul 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-06 21:16
Updated : 2026-07-07 15:16
NVD link : CVE-2026-59713
Mitre link : CVE-2026-59713
CVE.ORG link : CVE-2026-59713
JSON object : View
Products Affected
No product.
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
