PT-2024-37089 · Devika · Devika

Published

2024-06-28

·

Updated

2025-07-15

·

CVE-2024-5712

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: stitutionai/devika version latest
Description: A Cross-Site Request Forgery (CSRF) issue was identified, allowing attackers to perform unauthorized actions in the context of a victim's browser, such as deleting projects or changing application settings, without any CSRF protection implemented. Successful exploitation disrupts the integrity and availability of the application and its data.
Recommendations: For the latest version, update to a version that implements CSRF protection to prevent unauthorized actions. As a temporary workaround, consider implementing additional security measures to minimize the risk of exploitation, such as validating user requests to ensure they are legitimate.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-5712

Affected Products

Devika