CVE-2024-35108: CSRF
Published May 15, 2024
·Updated
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/homeProdeal.php?mudi=del&dataType=&dataTypeCN.
Affected Software
2 affected components
Sebrac Sebraccms
Sebrac Sebraccms=1.35
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 15, 2024
CVE Published
via NVD·02:15 AM
Aug 2, 2024
Data Sourced
via MITRE·03:10 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35108?
CVE-2024-35108 is classified as a medium severity vulnerability due to its potential impact on user security.
2
How do I fix CVE-2024-35108?
To fix CVE-2024-35108, implement CSRF protection mechanisms and validate requests properly in the affected component.
3
What causes CVE-2024-35108?
CVE-2024-35108 is caused by inadequate verification of requests in the admin functionality of idccms v1.35.
4
What are the consequences of exploiting CVE-2024-35108?
Exploiting CVE-2024-35108 could allow attackers to perform unauthorized actions on behalf of legitimate users.
5
Which versions of idccms are affected by CVE-2024-35108?
CVE-2024-35108 affects idccms version 1.35 specifically.