CVE-2024-40334: CSRF
Published Jul 10, 2024
·Updated
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/serverFiledeal.php?mudi=upFileDel&dataID=3
Affected Software
1 affected component
Sebrac Sebraccms=1.35
Event History
Jul 10, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-40334?
CVE-2024-40334 is classified as a medium severity vulnerability due to its Cross-Site Request Forgery (CSRF) nature.
2
How do I fix CVE-2024-40334?
To fix CVE-2024-40334, implement anti-CSRF tokens to protect the vulnerable endpoint in idccms v1.35.
3
What type of vulnerability is CVE-2024-40334?
CVE-2024-40334 is a Cross-Site Request Forgery (CSRF) vulnerability affecting idccms v1.35.
4
Which version of idccms is affected by CVE-2024-40334?
CVE-2024-40334 specifically affects idccms version 1.35.
5
What is the attack vector for CVE-2024-40334?
The attack vector for CVE-2024-40334 involves sending unauthorized requests to the vulnerable endpoint without user consent.