CVE-2024-56903: CSRF
Published Feb 3, 2025
·Updated
Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against critical functionalities, such as account management. This vulnerability is used in chain with CVE-2024-56901 for a successful CSRF attack.
Affected Software
1 affected component
GeoVision GV-ASWeb<6.1.1.0
Event History
Feb 3, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-56903?
CVE-2024-56903 has been classified as a high severity vulnerability due to its potential for unauthorized operations.
2
How do I fix CVE-2024-56903?
To mitigate CVE-2024-56903, upgrade Geovision GV-ASWeb to a version newer than 6.1.1.0.
3
What software is affected by CVE-2024-56903?
CVE-2024-56903 affects Geovision GV-ASWeb versions 6.1.1.0 and lower.
4
What type of vulnerability is CVE-2024-56903?
CVE-2024-56903 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
5
Can CVE-2024-56903 be exploited remotely?
Yes, CVE-2024-56903 can be exploited remotely by sending a crafted HTTP request.