8
CVE-2024-37774
- EPSS 0.14%
- Veröffentlicht 16.12.2024 22:15:06
- Zuletzt bearbeitet 20.06.2025 18:15:42
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sunbirddcim ≫ Dctrack Version9.1.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.349 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8 | 2.1 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.