PT-2024-15635 · Allegro · Allegro Rompager
Lorenzomoulin
·
Published
2024-01-14
·
Updated
2024-05-17
·
CVE-2024-0522
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Allegro RomPager version 4.01
Description
A problematic issue was found in the HTTP POST Request Handler component, specifically in the file usertable.htm?action=delete. The manipulation of the
username argument leads to cross-site request forgery. This issue can be exploited remotely. The vendor notes that this is a very old issue that was fixed 20 years ago without public disclosure.Recommendations
For Allegro RomPager version 4.01, upgrade to version 4.30 to address this issue. As a temporary workaround, consider restricting access to the usertable.htm?action=delete file or disabling the HTTP POST Request Handler component until the upgrade is applied.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Allegro Rompager