CVE-2024-35558: CSRF
Published May 22, 2024
·Updated
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/cadeal.php?mudi=rev&nohrefStr=close.
Affected Software
1 affected component
Sebrac Sebraccms
Event History
May 22, 2024
CVE Published
via MITRE·01:38 PM
Data Sourced
via MITRE·01:38 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-35558?
CVE-2024-35558 has been classified with a medium severity due to its potential impact on user security.
2
How do I fix CVE-2024-35558?
To fix CVE-2024-35558, implement token-based CSRF protection in the affected component to validate user requests.
3
What are the consequences of exploiting CVE-2024-35558?
Exploiting CVE-2024-35558 allows an attacker to perform unauthorized actions on behalf of authenticated users.
4
Which software versions are affected by CVE-2024-35558?
CVE-2024-35558 specifically affects idccms version 1.35.
5
Who is the vendor responsible for CVE-2024-35558?
The vendor responsible for CVE-2024-35558 is IDCCMS.