CVE-2024-35554: CSRF
Published May 22, 2024
·Updated
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWebdeal.php?mudi=del&dataType=newsWeb&dataTypeCN.
Affected Software
1 affected component
Sebrac Sebraccms
Event History
May 22, 2024
CVE Published
via MITRE·01:38 PM
Data Sourced
via MITRE·01:38 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-35554?
CVE-2024-35554 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-35554?
To fix CVE-2024-35554, ensure proper CSRF token validation is implemented on the /admin/infoWeb_deal.php component.
3
What is the impact of CVE-2024-35554?
The impact of CVE-2024-35554 allows an attacker to perform unauthorized actions on behalf of an authenticated user.
4
Which versions of IDCCMS are affected by CVE-2024-35554?
CVE-2024-35554 affects IDCCMS version 1.35.
5
What components are involved in CVE-2024-35554?
CVE-2024-35554 involves the /admin/infoWeb_deal.php component in IDCCMS.