CVE-2024-40329: CSRF
Published Jul 10, 2024
·Updated
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBakdeal.php?mudi=backup
Affected Software
2 affected components
Sebrac Sebraccms
Sebrac Sebraccms=1.35
Event History
Jul 10, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-40329?
CVE-2024-40329 is classified as a critical vulnerability due to its potential impact on user data and application integrity.
2
How do I fix CVE-2024-40329?
To fix CVE-2024-40329, implement CSRF tokens in state-changing requests to ensure proper validation.
3
What is the impact of CVE-2024-40329?
The impact of CVE-2024-40329 allows an attacker to perform unauthorized actions on behalf of authenticated users.
4
Is CVE-2024-40329 easy to exploit?
Yes, CVE-2024-40329 is relatively easy to exploit if an attacker can trick a user into executing an action through forged requests.
5
Which version of IDCCMS is affected by CVE-2024-40329?
CVE-2024-40329 specifically affects IDCCMS version 1.35.