CVE-2024-40331: CSRF
Published Jul 10, 2024
·Updated
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/dbBakMySQLdeal.php?mudi=backup
Affected Software
2 affected components
Sebrac Sebraccms
Sebrac Sebraccms=1.35
Event History
Jul 10, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-40331?
CVE-2024-40331 is classified as a moderate severity vulnerability due to its potential impact on application integrity through Cross-Site Request Forgery.
2
How do I fix CVE-2024-40331?
To fix CVE-2024-40331, implement anti-CSRF tokens in forms and validate user actions to prevent unauthorized requests.
3
What is the nature of the vulnerability CVE-2024-40331?
CVE-2024-40331 is a Cross-Site Request Forgery (CSRF) vulnerability found in idccms v1.35.
4
Which component is affected by CVE-2024-40331?
The vulnerable component affected by CVE-2024-40331 is the /admin/dbBakMySQL_deal.php script in idccms v1.35.
5
Can CVE-2024-40331 lead to data loss?
Yes, CVE-2024-40331 can lead to unauthorized data backup actions, which may result in data loss or exposure.