CVE-2024-36670: CSRF
Published Jun 5, 2024
·Updated
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClassdeal.php?mudi=del
Affected Software
2 affected components
Sebrac Sebraccms
Sebrac Sebraccms=1.35
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
Jun 5, 2024
CVE Published
via NVD·07:15 PM
Sep 15, 2024
Data Sourced
via MITRE·07:14 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-36670?
CVE-2024-36670 has been classified as a high severity vulnerability due to its potential to allow unauthorized actions on behalf of users.
2
How do I fix CVE-2024-36670?
To mitigate CVE-2024-36670, implement anti-CSRF tokens in forms that change application state and ensure proper validation of actions.
3
What systems are affected by CVE-2024-36670?
CVE-2024-36670 affects IDCCMS version 1.35, specifically through the admin/vpsClass_deal.php component.
4
What type of vulnerability is CVE-2024-36670?
CVE-2024-36670 is identified as a Cross-Site Request Forgery (CSRF) vulnerability.
5
What actions could be exploited due to CVE-2024-36670?
CVE-2024-36670 could allow an attacker to perform unauthorized administrative actions without user consent.