Allegro RomPager HTTP POST Request cross-site request forgery
CVE-2024-0522
4.3MEDIUM
What is CVE-2024-0522?
A vulnerability exists in Allegro RomPager 4.01 affecting the HTTP POST Request Handler, specifically through the manipulation of the username parameter within the usertable.htm?action=delete function. This weakness enables an attacker to execute cross-site request forgery (CSRF) attacks remotely, posing a significant risk to users and systems that utilize this outdated version. Although the vendor claims this issue was resolved two decades ago without public documentation, the absence of a timely update exposes users to exploitation. Users are strongly recommended to upgrade to version 4.30 to mitigate any potential security threats associated with this vulnerability.
Affected Version(s)
RomPager 4.01
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
CVSS V3.0
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
lorenzomoulin (VulDB User)
