CVE-2024-35556: CSRF
Published May 22, 2024
·Updated
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsSysdeal.php?mudi=infoSet.
Affected Software
1 affected component
Sebrac Sebraccms
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 22, 2024
CVE Published
via NVD·02:15 PM
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Aug 20, 2024
Data Sourced
via MITRE·02:23 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35556?
CVE-2024-35556 is classified as a high severity vulnerability due to its potential for Cross-Site Request Forgery exploits.
2
How do I fix CVE-2024-35556?
To fix CVE-2024-35556, implement anti-CSRF tokens and ensure proper validation of user input in the affected component.
3
What is affected by CVE-2024-35556?
CVE-2024-35556 affects IDCCMS version 1.35 specifically within the /admin/vpsSys_deal.php?mudi=infoSet component.
4
Can CVE-2024-35556 lead to data compromise?
Yes, CVE-2024-35556 can lead to unauthorized actions being taken on behalf of a user, potentially resulting in data compromise.
5
Is there a patch available for CVE-2024-35556?
As of now, there is no official patch released for CVE-2024-35556; users are advised to apply workarounds until a fix is provided.