CVE-2024-35109: CSRF
Published May 15, 2024
·Updated
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /homeProdeal.php?mudi=add&nohrefStr=close.
Affected Software
2 affected components
Sebrac Sebraccms
Sebrac Sebraccms=1.35
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 15, 2024
CVE Published
via NVD·02:15 AM
Aug 2, 2024
Data Sourced
via MITRE·03:10 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35109?
CVE-2024-35109 has a high severity rating due to its potential to allow Cross-Site Request Forgery (CSRF) attacks.
2
How do I fix CVE-2024-35109?
To fix CVE-2024-35109, implement CSRF tokens and validate requests to ensure they originate from authenticated users.
3
Which versions of IDCCMS are affected by CVE-2024-35109?
IDCCMS version 1.35 is affected by CVE-2024-35109.
4
What type of vulnerability is CVE-2024-35109?
CVE-2024-35109 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
5
What component is vulnerable in CVE-2024-35109?
The vulnerable component in CVE-2024-35109 is /homePro_deal.php via the parameter mudi=add.