PT-2024-33413 · Infomaniak · Vod Infomaniak

Joshua Chan

·

Published

2024-10-20

·

Updated

2024-10-22

·

CVE-2024-49274

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VOD Infomaniak versions 1.5.7 and earlier
Description The issue is a Cross-Site Request Forgery (CSRF) vulnerability, which allows an attacker to perform unauthorized actions on the affected system. This problem affects VOD Infomaniak, allowing Cross Site Request Forgery.
Recommendations For versions 1.5.7 and earlier, update to a version newer than 1.5.7 to resolve the issue. As a temporary workaround, consider implementing additional security measures to prevent Cross-Site Request Forgery attacks, such as validating user requests and ensuring that sensitive actions require explicit user confirmation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-49274

Affected Products

Vod Infomaniak