PT-2024-34311 · David Garcia · Domain Sharding

Soprobro

·

Published

2024-11-19

·

Updated

2024-11-19

·

CVE-2024-50533

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: David Garcia Domain Sharding versions 1.2.1 and earlier
Description: The issue is a Cross-Site Request Forgery (CSRF) vulnerability that allows Stored XSS. This means an attacker can trick a user into performing unintended actions on a web application, potentially leading to the execution of malicious scripts stored on the site.
Recommendations: For versions 1.2.1 and earlier, as a temporary workaround, consider implementing additional validation for requests to prevent CSRF attacks, and restrict access to sensitive functions that could be exploited through Stored XSS. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-50533

Affected Products

Domain Sharding