CVE-2024-35011: CSRF
Published May 14, 2024
·Updated
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoTypedeal.php?mudi=rev&nohrefStr=close.
Affected Software
2 affected components
Sebrac Sebraccms
Sebrac Sebraccms=1.35
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·04:17 PM
Aug 19, 2024
Data Sourced
via MITRE·04:38 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35011?
CVE-2024-35011 has a high severity level due to its ability to perform Cross-Site Request Forgery (CSRF).
2
How do I fix CVE-2024-35011?
To fix CVE-2024-35011, implement anti-CSRF tokens to secure the affected endpoints in IDCCMS.
3
What is Cross-Site Request Forgery as described in CVE-2024-35011?
Cross-Site Request Forgery in CVE-2024-35011 allows attackers to trick users into executing unwanted actions on the admin interface of IDCCMS.
4
Which components of IDCCMS are affected by CVE-2024-35011?
CVE-2024-35011 affects the /admin/infoType_deal.php component of IDCCMS.
5
What version of IDCCMS is impacted by CVE-2024-35011?
CVE-2024-35011 impacts IDCCMS version 1.35.