PT-2024-27744 · Sunbird Dcim · Dctrack

Published

2024-12-16

·

Updated

2024-12-17

·

CVE-2024-37774

CVSS v3.1

8.0

High

AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sunbird DCIM dcTrack version 9.1.2
Description A Cross-Site Request Forgery (CSRF) issue allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens. This can be exploited by attackers who are already logged in.
Recommendations For Sunbird DCIM dcTrack version 9.1.2, consider implementing anti-CSRF measures, such as token-based validation, to prevent attackers from forcing administrators to perform unintended actions. As a temporary workaround, restrict access to sensitive admin screens until a patch is available.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-37774

Affected Products

Dctrack