CVE-2024-36549: CSRF
Published Jun 4, 2024
·Updated
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompanydeal.php?mudi=rev&nohrefStr=close
Affected Software
1 affected component
Sebrac Sebraccms=1.35
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
Jun 4, 2024
CVE Published
via NVD·03:15 PM
Aug 14, 2024
Data Sourced
via MITRE·08:07 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-36549?
CVE-2024-36549 is classified as a medium-severity vulnerability due to its potential for exploitation via Cross-Site Request Forgery.
2
How do I fix CVE-2024-36549?
To fix CVE-2024-36549, update Idccms to the latest version that addresses this CSRF vulnerability.
3
What type of vulnerability is CVE-2024-36549?
CVE-2024-36549 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
What versions of Idccms are affected by CVE-2024-36549?
Idccms version 1.35 is affected by CVE-2024-36549.
5
What is the exploit path for CVE-2024-36549?
The exploit path for CVE-2024-36549 is through the /admin/vpsCompany_deal.php endpoint with specific query parameters.