CVE-2024-36076: CSRF
Published May 19, 2024
·Updated
Cross-Site WebSocket Hijacking in SysReptor from version 2024.28 to version 2024.30 causes attackers to escalate privileges and obtain sensitive information when a logged-in SysReptor user visits a malicious same-site subdomain in the same browser session.
Affected Software
2 affected components
SysReptor SysReptor>=2024.28<=2024.30
Syslifters Sysreptor>=2024.28<2024.40
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 19, 2024
CVE Published
via NVD·08:15 PM
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 2, 2024
Data Sourced
via MITRE·03:33 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-36076?
CVE-2024-36076 has a high severity due to its potential for privilege escalation and exposure of sensitive information.
2
How do I fix CVE-2024-36076?
To fix CVE-2024-36076, upgrade SysReptor to version 2024.40 or later.
3
Who is affected by CVE-2024-36076?
CVE-2024-36076 affects all users of SysReptor versions 2024.28 to 2024.30.
4
What type of attack is associated with CVE-2024-36076?
CVE-2024-36076 involves a Cross-Site WebSocket Hijacking attack targeting logged-in SysReptor users.
5
Can CVE-2024-36076 allow attackers to access user accounts?
Yes, CVE-2024-36076 can allow attackers to escalate their privileges and access sensitive information from user accounts.