OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross-Site Request Forgery (CSRF) attack. There are no workarounds that address this vulnerability and all users are advised to update their package.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| oro/crm(Packagist) | 3.1.0 | 4.1.17 | N/A |
| oro/crm(Packagist) | 4.2.0 | 4.2.7 | N/A |
CVSS Metrics