CVE-2024-37931
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 2, 2025
CWE ID 352
Summary
CVE-2024-37931 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Creativthemes Point. This issue allows attackers to manipulate users into making unintended actions on the affected website. The vulnerability can be exploited to perform unwanted functionalities, such as account takeover or data modification, on behalf of the targeted user. The CSRF flaw impacts Point versions from n/a through 1.1, necessitating immediate attention and mitigation efforts to safeguard against potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.