First published: Mon Aug 26 2024(Updated: )
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_playlist page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lopalopa Music Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42792 is recognized as a high-severity Cross-Site Request Forgery (CSRF) vulnerability.
To remediate CVE-2024-42792, implement CSRF tokens in form submissions for actions like deleting a playlist.
CVE-2024-42792 affects users of Kashipara Music Management System v1.0 specifically.
CVE-2024-42792 allows attackers to potentially delete a playlist without user consent through CSRF.
Yes, CVE-2024-42792 can be exploited without authentication if proper CSRF protections are not implemented.