First published: Wed Mar 13 2024(Updated: )
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_edit.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms v6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28432 is classified as a Cross-Site Request Forgery (CSRF) vulnerability which can lead to unauthorized actions being performed on behalf of a user.
To fix CVE-2024-28432, ensure that proper CSRF protection mechanisms are implemented in your DedeCMS application, particularly in the /dede/article_edit.php component.
CVE-2024-28432 specifically affects DedeCMS version 5.7.
The impact of CVE-2024-28432 allows attackers to perform malicious actions without the user's consent, potentially compromising user data and application integrity.
Yes, testing for CVE-2024-28432 involves attempts to forge requests to the vulnerable endpoint and checking for successful unauthorized actions.