CVE-2024-35559: CSRF
Published May 22, 2024
·Updated
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMovedeal.php?mudi=rev&nohrefStr=close.
Affected Software
1 affected component
Sebrac Sebraccms
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 22, 2024
CVE Published
via NVD·02:15 PM
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Aug 2, 2024
Data Sourced
via MITRE·03:21 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35559?
CVE-2024-35559 is classified as a critical vulnerability due to the potential for unauthorized actions via Cross-Site Request Forgery.
2
How do I fix CVE-2024-35559?
To fix CVE-2024-35559, implement anti-CSRF tokens in forms and validate user actions properly to prevent CSRF attacks.
3
What are the potential impacts of CVE-2024-35559?
The potential impacts of CVE-2024-35559 include unauthorized data modification and account compromise due to CSRF attacks.
4
Which component is affected by CVE-2024-35559?
CVE-2024-35559 affects the /admin/infoMove_deal.php component of idccms v1.35.
5
Is CVE-2024-35559 exploitable remotely?
Yes, CVE-2024-35559 is exploitable remotely, as it does not require local access to the affected server.