PT-2024-35819 · Unknown · Kevin'S Versions

Soprobro

·

Published

2024-12-02

·

Updated

2024-12-02

·

CVE-2024-53712

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Kevin's versions n/a through 2.0.0
Description The issue is a Cross-Site Request Forgery (CSRF) vulnerability that allows Stored XSS. This means an attacker can execute malicious scripts on a user's browser, potentially leading to unauthorized actions on the user's account.
Recommendations For versions n/a through 2.0.0, as a temporary workaround, consider implementing proper CSRF token validation to prevent unauthorized requests. Restrict access to sensitive operations that could be exploited through Stored XSS to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-53712

Affected Products

Kevin'S Versions