VYPR
High severity8.8NVD Advisory· Published Jun 8, 2021· Updated Jun 17, 2026

CVE-2020-26516

CVE-2020-26516

Description

A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entirely predicted allowing attackers to cause the victim's browser to execute undesired actions in the web application through crafted requests.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

14
  • Intland/Codebeamer12 versions
    cpe:2.3:a:intland:codebeamer:10.0.0:-:*:*:*:*:*:*+ 11 more
    • cpe:2.3:a:intland:codebeamer:10.0.0:-:*:*:*:*:*:*
    • cpe:2.3:a:intland:codebeamer:10.0.0:prerelease4:*:*:*:*:*:*
    • cpe:2.3:a:intland:codebeamer:10.0.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:intland:codebeamer:10.0.0:sp1:*:*:*:*:*:*
    • cpe:2.3:a:intland:codebeamer:10.0.0:sp2:*:*:*:*:*:*
    • cpe:2.3:a:intland:codebeamer:10.0.1:sp1:*:*:*:*:*:*
    • cpe:2.3:a:intland:codebeamer:10.1.0:-:*:*:*:*:*:*
    • cpe:2.3:a:intland:codebeamer:10.1.0:sp1:*:*:*:*:*:*
    • cpe:2.3:a:intland:codebeamer:10.1.0:sp2:*:*:*:*:*:*
    • cpe:2.3:a:intland:codebeamer:10.1.0:sp3:*:*:*:*:*:*
    • cpe:2.3:a:intland:codebeamer:10.1.0:sp4:*:*:*:*:*:*
    • cpe:2.3:a:intland:codebeamer:21.04:*:*:*:*:*:*:*
  • Intland/codeBeamer ALMcpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 10.x through 10.1.SP4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.