Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-26516 – A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.S

A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entirely predicted allowing attackers to cause the victim’s browser to execute undesired actions in the web application through crafted requests.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26516

Reference (s):

  • https://intland.com/codebeamer/application-lifecycle-management/
  • https://www.compass-security.com/fileadmin/Research/Advisories/2021-08_CSNC-2020-009-codebeamer_ALM_Missing-CSRF.txt
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2020-25057 - An issue was discovered on LG mobile devices with Android OS 10 software.

2021-current

CVE-2014-9235 - Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos

2021-current

CVE-2020-0828 - A remote code execution vulnerability exists in the way that the ChakraCo