CVE-2024-38732

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 2, 2025
CWE ID 352

Summary

CVE-2024-38732 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Patricia Blog from versions n/a through 1.2. An attacker can exploit this issue to force unintended actions from a victim's browser, potentially leading to unauthorized changes or data theft. The CSRF flaw lies within VolThemes Patricia Blog, enabling attackers to submit malicious requests on behalf of the victim, bypassing user authentication and authorization. This poses a significant risk to users who visit untrusted websites or click on malicious links.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share