First published: Tue Aug 20 2024(Updated: )
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=files
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pligg CMS | =2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42610 is classified with a medium severity level due to its potential impact on the security of Pligg CMS.
To fix CVE-2024-42610, apply the latest security updates from Pligg CMS or implement CSRF tokens in your forms to validate requests.
CVE-2024-42610 can be exploited through Cross-Site Request Forgery attacks, allowing unauthorized actions to be performed by users.
CVE-2024-42610 specifically affects Pligg CMS version 2.0.2; other versions should be evaluated for similar vulnerabilities.
The affected component in CVE-2024-42610 is the admin_backup.php script in Pligg CMS, which lacks proper CSRF protection.