CVE-2024-35039: CSRF
Published May 16, 2024
·Updated
idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/tplSysdeal.php?mudi=area.
Affected Software
2 affected components
Sebrac Sebraccms
Sebrac Sebraccms=1.35
Event History
May 16, 2024
CVE Published
via MITRE·02:29 PM
Data Sourced
via MITRE·02:29 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35039?
CVE-2024-35039 is classified as a moderate severity vulnerability due to its potential impact on administrative functions.
2
How does CVE-2024-35039 affect idccms users?
CVE-2024-35039 allows attackers to exploit Cross-Site Request Forgery vulnerabilities, potentially compromising admin functionalities without user interaction.
3
What versions of idccms are affected by CVE-2024-35039?
CVE-2024-35039 affects idccms versions prior to V1.36, specifically in V1.35.
4
How do I fix CVE-2024-35039?
To fix CVE-2024-35039, update idccms to version V1.36 or later, which addresses the CSRF vulnerability.
5
Can CVE-2024-35039 be exploited remotely?
Yes, CVE-2024-35039 can be exploited remotely, allowing attackers to perform unauthorized actions as an administrator.