First published: Thu Jan 18 2024(Updated: )
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/add_group_save
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FlyCms | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22593 is classified as a medium severity vulnerability due to the potential impact of Cross-Site Request Forgery (CSRF).
To fix CVE-2024-22593, it is recommended to implement CSRF tokens in the form submissions in the affected route /system/admin/add_group_save.
CVE-2024-22593 affects FlyCms version 1.0, specifically in its handling of form submissions for adding groups.
CVE-2024-22593 is a Cross-Site Request Forgery (CSRF) vulnerability, allowing unauthorized actions on behalf of the user.
Yes, CVE-2024-22593 can allow attackers to perform actions on behalf of users without their consent, potentially leading to unauthorized changes.