PT-2025-3072 · Spagobi · Spagobi

Mariotesoro

·

Published

2025-01-21

·

Updated

2025-10-17

·

CVE-2024-54792

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SpagoBI version 3.5.1
Description A Cross-Site Request Forgery (CSRF) issue has been found in the user administration panel. An authenticated user can lead another user into executing unwanted actions inside the application they are logged in, such as adding, editing, or deleting users.
Recommendations For SpagoBI version 3.5.1, consider disabling access to the user administration panel until a patch is available to prevent potential exploitation of the CSRF issue. Restrict access to sensitive functions like adding, editing, or deleting users to minimize the risk of unwanted actions being executed.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-54792

Affected Products

Spagobi