CVE-2024-54792: CSRF
A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead another user into executing unwanted actions inside the application they are logged in, like adding, editing or deleting users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54792?
CVE-2024-54792 is categorized as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2024-54792?
To fix CVE-2024-54792, apply available patches for SpagoBI v3.5.1 or implement CSRF protection mechanisms in the user administration panel.
Who is affected by CVE-2024-54792?
CVE-2024-54792 affects authenticated users of SpagoBI version 3.5.1, particularly in the user administration panel.
What actions can be exploited in CVE-2024-54792?
CVE-2024-54792 allows an authenticated user to manipulate another user's session to perform actions like adding, editing, or deleting users.
Is CVE-2024-54792 easy to exploit?
Yes, CVE-2024-54792 can be exploited with minimal technical knowledge, as it relies on social engineering to trick users into executing unintended actions.