CVE-2024-37467

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 2, 2025
CWE ID 352

Summary

CVE-2024-37467 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the ThemeIsle Hestia theme, versions from n/a to 3.1.2. Malicious actors can exploit this issue to perform unintended actions on behalf of a user, making it crucial for users to update their theme to a patched version as soon as possible. CSRF attacks can lead to serious consequences, including data manipulation or unauthorized account actions, making this a significant security concern. The vulnerability arises due to insufficient input validation and authorization checks, enabling attackers to trick users into executing malicious requests.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share