CVE-2024-38293: CSRF
Published Jun 13, 2024
·Updated
ALCASAR before 3.6.1 allows CSRF and remote code execution in activity.php.
Affected Software
2 affected components
ALCASAR ALCASAR<3.6.1
ALCASAR ALCASAR<3.6.1
Event History
Jun 13, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-38293?
CVE-2024-38293 has a high severity due to its potential for CSRF and remote code execution.
2
How do I fix CVE-2024-38293?
To fix CVE-2024-38293, upgrade your ALCASAR installation to version 3.6.1 or later.
3
What software is affected by CVE-2024-38293?
CVE-2024-38293 affects ALCASAR versions prior to 3.6.1.
4
What types of attacks can be executed using CVE-2024-38293?
CVE-2024-38293 allows for CSRF attacks and enables remote code execution.
5
What is the impact of CVE-2024-38293 on system security?
The impact of CVE-2024-38293 could lead to unauthorized actions and code execution on the affected system.