PT-2024-34616 · Jatos · Jatos

Published

2024-11-05

·

Updated

2025-06-24

·

CVE-2024-51381

CVSS v3.1

8.4

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JATOS version 3.9.3
Description A Cross-Site Request Forgery (CSRF) issue allows attackers to perform actions reserved for administrators, including creating admin accounts. This flaw can lead to unauthorized activities, compromising the security and integrity of the platform, especially if an attacker gains administrative control.
Recommendations For JATOS version 3.9.3, update to a newer version that contains a fix for this issue to prevent unauthorized administrative actions. As a temporary workaround, consider restricting access to administrative functions to minimize the risk of exploitation.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-51381

Affected Products

Jatos