{"id":"CVE-2021-39198","details":"OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross-Site Request Forgery (CSRF) attack. There are no workarounds that address this vulnerability and all users are advised to update their package.","aliases":["GHSA-vf7h-6246-hm43"],"modified":"2026-07-08T06:28:25.776304462Z","published":"2021-11-19T22:15:07.450Z","database_specific":{"unresolved_ranges":[{"source":"CPE_RANGE","vendor_product":"oroinc:client_relationship_management","cpes":["cpe:2.3:a:oroinc:client_relationship_management:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.1.0"},{"last_affected":"3.1.24"},{"introduced":"4.1.0"},{"last_affected":"4.1.15"}]}]},"references":[{"type":"ADVISORY","url":"https://github.com/oroinc/crm/security/advisories/GHSA-vf7h-6246-hm43"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/oroinc/crm","events":[{"introduced":"ef6e3621ee08b97db11c2664546c6c979b86651a"},{"last_affected":"e556baa1f84b42caa6d68c36cd779681262a4e08"}],"database_specific":{"extracted_events":[{"introduced":"4.2.0"},{"last_affected":"4.2.5"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:oroinc:client_relationship_management:*:*:*:*:*:*:*:*"}}],"versions":["4.2.5","4.2.3","4.2.2","4.2.1","4.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-39198.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"}]}