CVE-2024-56116
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Dec 18, 2024
Updated: Dec 31, 2024
CWE ID 352
Summary
CVE-2024-56116 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Amiro.CMS versions prior to 7.8.4. This issue enables remote attackers to craft malicious requests that can be executed in the context of an unsuspecting user, leading to the creation of an administrator account. Successful exploitation of this vulnerability could result in unauthorized access to the CMS system, potentially leading to data theft or modification. It is crucial for Amiro.CMS users to upgrade to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.