CVE-2024-37421
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 2, 2025
CWE ID 352
Summary
CVE-2024-37421 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the JobScout feature in Rara Theme. This issue permits an attacker to submit malicious requests on behalf of a victim, who is currently authenticated to the affected application. This vulnerability poses a risk for unintended actions on the victim's behalf, such as data manipulation or unauthorized changes to account settings. JobScot versions from n/a through 1.1.4 have been identified as vulnerable to this issue. Users are advised to update their software to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.