CVE-2024-35552: CSRF
Published May 22, 2024
·Updated
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMovedeal.php?mudi=del&dataType=logo&dataTypeCN.
Affected Software
1 affected component
Sebrac Sebraccms
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 22, 2024
CVE Published
via NVD·02:15 PM
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Nov 1, 2024
Data Sourced
via MITRE·05:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35552?
CVE-2024-35552 has a medium severity rating due to its potential to allow unauthorized actions via Cross-Site Request Forgery.
2
How do I fix CVE-2024-35552?
To fix CVE-2024-35552, implement anti-CSRF tokens in requests to the vulnerable component /admin/infoMove_deal.php.
3
What systems are affected by CVE-2024-35552?
CVE-2024-35552 affects IDCCMS version 1.35.
4
Can CVE-2024-35552 lead to data loss?
Yes, CVE-2024-35552 can potentially lead to data loss by allowing unauthorized deletion of resources.
5
What type of attack does CVE-2024-35552 involve?
CVE-2024-35552 involves a Cross-Site Request Forgery (CSRF) attack vector.