A Cross-Site Request Forgery (CSRF) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x could allow with some very specific conditions an attacker to send a specifically crafted query to the server.
- https://www.3ds.com/vulnerability/advisories
- https://github.com/fkie-cad/nvd-json-data-feeds