CVE-2024-28677: CSRF
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/articlekeywordsmain.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28677?
CVE-2024-28677 is considered a medium severity vulnerability due to its potential to allow unauthorized actions without user interaction.
How do I fix CVE-2024-28677?
To fix CVE-2024-28677, ensure that you implement CSRF tokens in your forms to prevent unauthorized requests.
What is a Cross-Site Request Forgery in relation to CVE-2024-28677?
A Cross-Site Request Forgery (CSRF) in CVE-2024-28677 allows an attacker to perform actions on behalf of a victim user without their consent.
Which versions of DedeCMS are affected by CVE-2024-28677?
CVE-2024-28677 affects DedeCMS version 5.7 and potentially other versions that share the same vulnerability.
What is the potential impact of exploiting CVE-2024-28677?
Exploiting CVE-2024-28677 could lead to unauthorized article keyword manipulation and other malicious actions performed on behalf of authenticated users.