PT-2024-24033 · Unknown+11 · Emmet Lite+14

Dhabaleshwar Das

·

Published

2024-04-10

·

Updated

2024-04-10

·

CVE-2024-31386

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions X-T9 versions 1.19.0 and earlier Lightning versions 15.18.0 and earlier Default Mag versions 1.3.5 and earlier Namaha versions 1.0.40 and earlier CityLogic versions 1.1.29 and earlier i-max versions 1.6.2 and earlier Emmet Lite versions 1.7.5 and earlier Decode versions 3.15.3 and earlier Sliding Door versions 3.3 and earlier Shopstar! versions 1.1.33 and earlier Gridsby versions 1.3.0 and earlier HappenStance versions 3.0.1 and earlier i-excel versions 1.7.9 and earlier Panoramic versions 1.1.56 and earlier Sensible WP versions 1.3.1 and earlier
Description A Cross-Site Request Forgery (CSRF) issue affects multiple themes. This issue allows an attacker to perform actions on behalf of a user without their knowledge.
Recommendations For X-T9 versions 1.19.0 and earlier, update to a version that includes a fix for this issue. For Lightning versions 15.18.0 and earlier, update to a version that includes a fix for this issue. For Default Mag versions 1.3.5 and earlier, update to a version that includes a fix for this issue. For Namaha versions 1.0.40 and earlier, update to a version that includes a fix for this issue. For CityLogic versions 1.1.29 and earlier, update to a version that includes a fix for this issue. For i-max versions 1.6.2 and earlier, update to a version that includes a fix for this issue. For Emmet Lite versions 1.7.5 and earlier, update to a version that includes a fix for this issue. For Decode versions 3.15.3 and earlier, update to a version that includes a fix for this issue. For Sliding Door versions 3.3 and earlier, update to a version that includes a fix for this issue. For Shopstar! versions 1.1.33 and earlier, update to a version that includes a fix for this issue. For Gridsby versions 1.3.0 and earlier, update to a version that includes a fix for this issue. For HappenStance versions 3.0.1 and earlier, update to a version that includes a fix for this issue. For i-excel versions 1.7.9 and earlier, update to a version that includes a fix for this issue. For Panoramic versions 1.1.56 and earlier, update to a version that includes a fix for this issue. For Sensible WP versions 1.3.1 and earlier, update to a version that includes a fix for this issue.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-31386

Affected Products

Citylogic
Decode
Default Mag
Emmet Lite
Gridsby
Happenstance
Lightning
Namaha
Panoramic
Sensible Wp
Shopstar!
Sliding Door
X-T9
I-Excel
I-Max