CVE-2024-51156: CSRF
Published Nov 14, 2024
·Updated
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component 'erp.07fly.net:80/admin/SysNotifyUser/del.html?id=93'.
Affected Software
2 affected components
07FLYCMS 07FLYCMS
07FLY 07FLYCMS=1.3.9
Event History
Nov 14, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-51156?
CVE-2024-51156 is classified as a high severity vulnerability due to its potential for causing unauthorized actions on behalf of users.
2
What type of vulnerability is CVE-2024-51156?
CVE-2024-51156 is a Cross-Site Request Forgery (CSRF) vulnerability.
3
How do I fix CVE-2024-51156?
To fix CVE-2024-51156, implement anti-CSRF tokens in all forms to validate requests.
4
Who is affected by CVE-2024-51156?
Users of 07FLYCMS version 1.3.9 are affected by CVE-2024-51156.
5
What is the impact of CVE-2024-51156?
The impact of CVE-2024-51156 includes unauthorized actions that can be performed by attackers on behalf of authenticated users.