First published: Tue Jan 07 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team Bus Ticket Booking with Seat Reservation allows Cross Site Request Forgery.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through 5.4.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Magepeople Bus Ticket Booking With Seat Reservation | <=5.4.3 | |
WordPress WpBusTicketly | <=5.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49294 is classified as a critical Cross-Site Request Forgery (CSRF) vulnerability.
To fix CVE-2024-49294, upgrade the MagePeople Bus Ticket Booking with Seat Reservation or WordPress WpBusTicketly to the latest version beyond 5.4.3.
CVE-2024-49294 affects MagePeople Bus Ticket Booking with Seat Reservation and WordPress WpBusTicketly up to version 5.4.3.
CVE-2024-49294 allows attackers to exploit Cross-Site Request Forgery to perform actions on behalf of authenticated users.
Any users of MagePeople Bus Ticket Booking with Seat Reservation and WordPress WpBusTicketly versions up to 5.4.3 are at risk from CVE-2024-49294.