← Vulnerability feed

Vulnerability record · CVE-2021-41916 · published 8 October 2021

CVE-2021-41916: Webtareas project webtareas cross-site request forgery vulnerability

WWebtareas Project · Webtareas

A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new administrative profile and add a new user to the new profile. without the victim's knowledge, by enticing an authenticated admin user to visit an attacker's web page.

8.8 CVSS 3.1 High EPSS 0.82% · top 44.3% CWE-352 · Cross-site request forgery
8.8CVSS 3.1 base score, v2 6.8
0.82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new administrative profile and add a new user to the new profile. without the victim's knowledge, by enticing an authenticated admin user to visit an attacker's web page.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41916 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-44290Webtareas project webtareas sql injection vulnerabilitywebTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.EPSS 3.7%9.8CVE-2022-44291Webtareas project webtareas sql injection vulnerabilitywebTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.EPSS 3.7%9.8CVE-2021-43481Webtareas project webtareas sql injection vulnerabilityAn SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.EPSS 5.6%9.3CVE-2023-53972Webtareas project webtareas sql injection vulnerabilityWebTareas 2.4 contains a SQL injection vulnerability in the webTareasSID cookie parameter that allows unauthenticated attackers to manipulate databas…EPSS 0.43%8.8CVE-2021-41919Webtareas project webtareas unrestricted file upload vulnerabilitywebTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is workin…EPSS 2.4%8.7CVE-2023-53971Webtareas project webtareas unrestricted file upload vulnerabilityWebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functi…EPSS 0.48%7.5CVE-2021-41920Webtareas project webtareas sql injection vulnerabilitywebTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/libr…EPSS 1.7%7.5CVE-2020-25733Webtareas project webtareas unrestricted file upload vulnerabilitywebTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2021-41916), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.