CVE-2024-42605: CSRF
Published Aug 20, 2024
·Updated
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/editpage.php?linkid=1
Affected Software
1 affected component
Pligg Pligg CMS=2.0.2
Event History
Aug 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-42605?
CVE-2024-42605 is considered a moderate severity Cross-Site Request Forgery vulnerability in Pligg CMS v2.0.2.
2
How do I fix CVE-2024-42605?
To fix CVE-2024-42605, upgrade to a version of Pligg CMS that contains the patch for this CSRF vulnerability.
3
What is the impact of CVE-2024-42605?
The impact of CVE-2024-42605 includes potential unauthorized actions being performed on behalf of authenticated users.
4
Is CVE-2024-42605 exploitable remotely?
Yes, CVE-2024-42605 is exploitable remotely if an attacker tricks an authenticated user into clicking a malicious link.
5
Which versions of Pligg CMS are affected by CVE-2024-42605?
CVE-2024-42605 specifically affects Pligg CMS version 2.0.2.