CVE-2024-52420

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Nov 19, 2024
CWE ID 352

Summary

CVE-2024-52420 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Disable Admin Notices individually, version n/a through 1.3.5. An attacker can exploit this issue to perform unauthorized actions on a user's account, such as modifying settings or making unintended changes. The vulnerability arises from insufficient input validation, allowing malicious requests to be sent on behalf of the user. Successful attacks require the attacker to have prior knowledge of the user's session ID or to have already gained access to their account through other means. Users are advised to update their Disable Admin Notices plugin to a patched version to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share