In the administration of a Tracker, in the "Canned responses", there is no CSRF protection when creating, updating or deleting a canned response.
Impact
An attacker could use this vulnerability to trick victims into changing the canned responses.
CVSSv3.1 score: 4.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L)
References
CWE 352
Cross-Site Request Forgery - OWASP
CVE-2025-48991