CVE-2024-54792

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 21, 2025
CWE ID 352

Summary

CVE-2024-54792 is a newly discovered Cross-Site Request Forgery (CSRF) vulnerability affecting SpagoBI v3.5.1. This issue lies in the user administration panel, enabling an authenticated user to manipulate another user's session unknowingly. The attacker can instigate unwanted actions, such as adding, editing, or deleting users, without the victim's consent. This poses a significant risk to the security and integrity of user data within the application.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • SpagoBI

Affected Vendors

  • Engineering Ingegneria Informatica S.p.A.