CVE-2024-37421

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 2, 2025
CWE ID 352

Summary

CVE-2024-37421 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the JobScout feature in Rara Theme. This issue permits an attacker to submit malicious requests on behalf of a victim, who is currently authenticated to the affected application. This vulnerability poses a risk for unintended actions on the victim's behalf, such as data manipulation or unauthorized changes to account settings. JobScot versions from n/a through 1.1.4 have been identified as vulnerable to this issue. Users are advised to update their software to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share