CVE-2024-48278: CSRF
Published Oct 15, 2024
·Updated
Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php.
Affected Software
2 affected components
Phpgurukul User Registration & Login and User Management System
Phpgurukul User Registration \& Login And User Management System=3.2
Event History
Oct 15, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-48278?
CVE-2024-48278 is classified as a medium severity Cross Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-48278?
To fix CVE-2024-48278, implement CSRF tokens for state-changing requests in the application.
3
What are the implications of CVE-2024-48278?
Exploitation of CVE-2024-48278 allows attackers to perform unauthorized actions on behalf of authenticated users.
4
Which software is affected by CVE-2024-48278?
CVE-2024-48278 affects Phpgurukul User Registration & Login and User Management System version 3.2.
5
How can CVE-2024-48278 be exploited?
CVE-2024-48278 can be exploited by tricking an authenticated user into clicking a malicious link that submits a request to /edit-profile.php.