Sceawere

Vulnerability Detail

CVE-2026-19966UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CodeCanyon TimeCamp Integration Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
3h ago
Vendor
CodeCanyon
Product
TimeCamp Integration for CRM
Attack Type
Authorization Bypass
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affects some unknown processing of the file /clients/save_contact of the component Contact Information Update. Such manipulation of the argument contact_id leads to authorization bypass. The attack can be launched remotely. The exploit is publicly available and might be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-08-17T01:16:44.200Z",
  "pubdate": "2026-08-17T01:16:44.200Z",
  "executiveSummary": "An authorization bypass vulnerability has been identified in the CodeCanyon TimeCamp Integration for CRM plugin, specifically within the Contact Information Update component handling the /clients/save_contact endpoint. This security flaw enables remote attackers to manipulate the contact_id parameter to bypass intended access controls and execute unauthorized operations. The vulnerability affects software versions up to 2.8. Given that an exploit is publicly available and active exploitation is feasible over the network without prior authentication or elevated privileges, the risk implications are critical. Successful exploitation compromises the confidentiality and integrity of contact data within the CRM system, potentially allowing unauthorized modifications or data exposure. Organizations utilizing affected versions must prioritize remediation to prevent unauthorized data manipulation by remote threat actors leveraging the publicly accessible exploit vectors.",
  "technicalDetails": "The vulnerability resides in the Contact Information Update component of the CodeCanyon TimeCamp Integration for CRM plugin, specifically targeting the request processing logic implemented within the /clients/save_contact file path. The root cause of the authorization bypass is the insufficient validation and verification of user permissions and session state relative to the supplied parameter values during contact modification requests.\nSpecifically, the application processes the contact_id argument submitted via HTTP requests without rigorously asserting whether the authenticated or unauthenticated session possesses the requisite authorization to modify the specified contact record. Consequently, an attacker can manipulate the contact_id parameter value to reference arbitrary records belonging to other users or tenants within the CRM ecosystem.\nThe attack flow proceeds as follows: First, a remote attacker identifies the exposed endpoint at /clients/save_contact. Second, the attacker crafts a malicious HTTP request containing a targeted, arbitrary contact_id value. Third, due to the absence of robust server-side access control checks linked to the session context and the requested resource identifier, the application accepts the manipulated parameter and processes the update operation. The payload behavior involves submitting modified contact data that overwrites or interacts with the targeted record.\nThe affected versions encompass all releases of CodeCanyon TimeCamp Integration for CRM up to version 2.8. The vulnerability is exploitable remotely over the network, requiring no specialized authentication or elevated user privileges. The post-exploitation impact includes unauthorized modification, corruption, or potential disclosure of sensitive contact information managed by the CRM component, undermining the overall security posture of the hosting web application."
}
CVE-2026-19966: CodeCanyon TimeCamp Integration Authorization Bypass (MEDIUM Severity, CVSS: 5.4) - Sceawere