CVE-2024-51157: CSRF
Published Nov 8, 2024
·Updated
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component http://erp.07fly.net:80/oa/OaSchedule/add.html.
Affected Software
2 affected components
07FLYCMS 07FLYCMS
07FLY 07FLYCMS=1.3.9
Event History
Nov 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-51157?
CVE-2024-51157 is rated as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-51157?
To fix CVE-2024-51157, implement anti-CSRF tokens to validate requests.
3
What components are affected by CVE-2024-51157?
CVE-2024-51157 affects the 07FLYCMS V1.3.9 application.
4
How can CVE-2024-51157 be exploited?
CVE-2024-51157 can be exploited by tricking authenticated users into submitting unauthorized requests.
5
Is there a patch available for CVE-2024-51157?
Currently, there is no official patch available for CVE-2024-51157; mitigation through secure coding practices is recommended.