CVE-2024-36667: CSRF
Published Jun 5, 2024
·Updated
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/idcProTypedeal.php?mudi=add&nohrefStr=close
Affected Software
1 affected component
Idccms Project Idccms=1.35
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
Jun 5, 2024
CVE Published
via NVD·07:15 PM
Aug 21, 2024
Data Sourced
via MITRE·03:24 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-36667?
CVE-2024-36667 is classified as a medium-severity vulnerability due to its potential impact on user sessions.
2
How do I fix CVE-2024-36667?
To fix CVE-2024-36667, implement CSRF tokens in forms and validate them on the server-side before processing requests.
3
What specific component is affected by CVE-2024-36667?
CVE-2024-36667 affects the /admin/idcProType_deal.php component in idccms v1.35.
4
Is user authentication necessary for exploiting CVE-2024-36667?
Exploiting CVE-2024-36667 does not require user authentication, making it particularly concerning.
5
Which version of idccms is vulnerable to CVE-2024-36667?
idccms version 1.35 is the only version confirmed to be vulnerable to CVE-2024-36667.