CVE-2024-22699: CSRF
Published Jan 18, 2024
·Updated
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/updategroupsave.
Affected Software
1 affected component
Flycms Project Flycms=1.0
Event History
Jan 18, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-22699?
CVE-2024-22699 is considered a medium severity vulnerability.
2
How do I fix CVE-2024-22699?
To fix CVE-2024-22699, implement anti-CSRF tokens in the affected endpoint.
3
What is the affected version for CVE-2024-22699?
CVE-2024-22699 affects FlyCms version 1.0.
4
What type of vulnerability is CVE-2024-22699?
CVE-2024-22699 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Which endpoint is vulnerable in CVE-2024-22699?
The /system/admin/update_group_save endpoint is vulnerable in CVE-2024-22699.