CVE-2024-45987

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Sep 26, 2024
Updated: Oct 5, 2024
CWE ID 352

Summary

CVE-2024-45987 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Projectworld Online Voting System Version 1.0. This issue enables an attacker to manipulate an authenticated user's session to submit unwanted votes for a specific party through the voter.php page. The attacker creates a malicious link that, when clicked by an unsuspecting user, automatically submits a vote without the user's consent, posing a significant risk to the integrity of the online voting process.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share