PT-2024-24033 · Unknown+11 · Emmet Lite+14
Dhabaleshwar Das
·
Published
2024-04-10
·
Updated
2024-04-10
·
CVE-2024-31386
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
X-T9 versions 1.19.0 and earlier
Lightning versions 15.18.0 and earlier
Default Mag versions 1.3.5 and earlier
Namaha versions 1.0.40 and earlier
CityLogic versions 1.1.29 and earlier
i-max versions 1.6.2 and earlier
Emmet Lite versions 1.7.5 and earlier
Decode versions 3.15.3 and earlier
Sliding Door versions 3.3 and earlier
Shopstar! versions 1.1.33 and earlier
Gridsby versions 1.3.0 and earlier
HappenStance versions 3.0.1 and earlier
i-excel versions 1.7.9 and earlier
Panoramic versions 1.1.56 and earlier
Sensible WP versions 1.3.1 and earlier
Description
A Cross-Site Request Forgery (CSRF) issue affects multiple themes. This issue allows an attacker to perform actions on behalf of a user without their knowledge.
Recommendations
For X-T9 versions 1.19.0 and earlier, update to a version that includes a fix for this issue.
For Lightning versions 15.18.0 and earlier, update to a version that includes a fix for this issue.
For Default Mag versions 1.3.5 and earlier, update to a version that includes a fix for this issue.
For Namaha versions 1.0.40 and earlier, update to a version that includes a fix for this issue.
For CityLogic versions 1.1.29 and earlier, update to a version that includes a fix for this issue.
For i-max versions 1.6.2 and earlier, update to a version that includes a fix for this issue.
For Emmet Lite versions 1.7.5 and earlier, update to a version that includes a fix for this issue.
For Decode versions 3.15.3 and earlier, update to a version that includes a fix for this issue.
For Sliding Door versions 3.3 and earlier, update to a version that includes a fix for this issue.
For Shopstar! versions 1.1.33 and earlier, update to a version that includes a fix for this issue.
For Gridsby versions 1.3.0 and earlier, update to a version that includes a fix for this issue.
For HappenStance versions 3.0.1 and earlier, update to a version that includes a fix for this issue.
For i-excel versions 1.7.9 and earlier, update to a version that includes a fix for this issue.
For Panoramic versions 1.1.56 and earlier, update to a version that includes a fix for this issue.
For Sensible WP versions 1.3.1 and earlier, update to a version that includes a fix for this issue.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Citylogic
Decode
Default Mag
Emmet Lite
Gridsby
Happenstance
Lightning
Namaha
Panoramic
Sensible Wp
Shopstar!
Sliding Door
X-T9
I-Excel
I-Max