CVE-2024-39021: CSRF
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApiDatadeal.php?mudi=del
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39021?
CVE-2024-39021 is categorized with a high severity due to its potential for allowing unauthorized actions through Cross-Site Request Forgery.
How do I fix CVE-2024-39021?
To fix CVE-2024-39021, implement CSRF tokens in your forms to validate requests and ensure user actions are intentional.
What is affected by CVE-2024-39021?
CVE-2024-39021 affects Idccms version 1.35 through its vulnerability in the admin component handling vpsApiData.
What type of attack is CVE-2024-39021 associated with?
CVE-2024-39021 is associated with Cross-Site Request Forgery (CSRF), allowing attackers to perform actions on behalf of authenticated users.
Is there an exploit available for CVE-2024-39021?
Yes, the exploit for CVE-2024-39021 can be crafted to leverage the CSRF vulnerability present in the affected software component.