PT-2024-27744 · Sunbird Dcim · Dctrack
Published
2024-12-16
·
Updated
2024-12-17
·
CVE-2024-37774
CVSS v3.1
8.0
High
| AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sunbird DCIM dcTrack version 9.1.2
Description
A Cross-Site Request Forgery (CSRF) issue allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens. This can be exploited by attackers who are already logged in.
Recommendations
For Sunbird DCIM dcTrack version 9.1.2, consider implementing anti-CSRF measures, such as token-based validation, to prevent attackers from forcing administrators to perform unintended actions. As a temporary workaround, restrict access to sensitive admin screens until a patch is available.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dctrack