PT-2024-3156 · Unknown · Valvepress Automatic

Rafie Muhammad

·

Published

2024-02-25

·

Updated

2024-04-22

·

CVE-2024-32693

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:P/I:C/A:P
Name of the Vulnerable Software and Affected Versions ValvePress Automatic versions prior to 3.93.0
Description The issue is related to a Cross-Site Request Forgery (CSRF) vulnerability. This vulnerability is due to incorrect validation of the nonce value, which can allow a remote attacker to perform a CSRF attack.
Recommendations For versions prior to 3.93.0, update to version 3.93.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive functions that may be exploited through CSRF attacks until the update is applied.

Fix

CSRF

Weakness Enumeration

Related Identifiers

BDU:2024-03369
CVE-2024-32693

Affected Products

Valvepress Automatic