CVE-2024-50966

CVSS 3.1 Score 9.3 of 10 (high)

Details

Published Nov 8, 2024
CWE ID 352

Summary

CVE-2024-50966 is a newly disclosed vulnerability affecting the dingfanzu CMS V1.0. This issue involves a Cross-Site Request Forgery (CSRF) security flaw located in the /admin/doAdminAction.php?act=addAdmin component. A successful exploit of this vulnerability allows an attacker to perform unintended actions on the affected website by tricking a legitimate user into executing a malicious request. This can result in data modification, unauthorized access, and other potential security risks. It is recommended that users upgrade to the latest version of the CMS or take other mitigation measures to protect against CSRF attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share