CVE-2024-4589: DedeCMS mytag_edit.php cross-site request forgery
A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/mytagedit.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263311. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4589?
CVE-2024-4589 has been declared as a problematic vulnerability, indicating a moderate severity.
What type of attack is associated with CVE-2024-4589?
CVE-2024-4589 is associated with a cross-site request forgery (CSRF) attack.
How can CVE-2024-4589 be exploited?
CVE-2024-4589 can be exploited remotely through specific manipulations of the file /src/dede/mytag_edit.php.
What software version is affected by CVE-2024-4589?
CVE-2024-4589 specifically affects DedeCMS version 5.7.
How do I fix CVE-2024-4589?
To fix CVE-2024-4589, apply appropriate security patches or updates provided by DedeCMS, if available.