CVE-2024-38766

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 2, 2025
CWE ID 352

Summary

CVE-2024-38766 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Matomo Analytics. The issue allows malicious actors to submit unintended commands or actions on behalf of users, by forging requests to the Matomo server. This vulnerability affects all versions of Matomo Analytics from n/a through 5.1.1. Successful exploitation could lead to unauthorized modification of data, including the creation or deletion of reports, or even the unauthorized installation of add-ons. Users are strongly advised to update their Matomo Analytics installations as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share