CVE-2024-27631: CSRF
Published Apr 8, 2024
·Updated
Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php
Affected Software
2 affected components
GNU Savane<3.12
GNU Savane<3.13
Remediation
Event History
Apr 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27631?
CVE-2024-27631 has a medium severity level due to its potential to allow privilege escalation.
2
How do I fix CVE-2024-27631?
To fix CVE-2024-27631, upgrade GNU Savane to version 3.12 or later.
3
Who is affected by CVE-2024-27631?
CVE-2024-27631 affects all versions of GNU Savane up to and including 3.12.
4
What type of vulnerability is CVE-2024-27631?
CVE-2024-27631 is classified as a Cross Site Request Forgery (CSRF) vulnerability.
5
Can CVE-2024-27631 be exploited remotely?
Yes, CVE-2024-27631 can be exploited remotely by attackers to escalate privileges.