Allegro RomPager HTTP POST Request cross-site request forgery
CVE-2024-0522

4.3MEDIUM

Key Information:

Vendor

Allegro

Status
Vendor
CVE Published:
14 January 2024

What is CVE-2024-0522?

A vulnerability exists in Allegro RomPager 4.01 affecting the HTTP POST Request Handler, specifically through the manipulation of the username parameter within the usertable.htm?action=delete function. This weakness enables an attacker to execute cross-site request forgery (CSRF) attacks remotely, posing a significant risk to users and systems that utilize this outdated version. Although the vendor claims this issue was resolved two decades ago without public documentation, the absence of a timely update exposes users to exploitation. Users are strongly recommended to upgrade to version 4.30 to mitigate any potential security threats associated with this vulnerability.

Affected Version(s)

RomPager 4.01

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

CVSS V3.0

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lorenzomoulin (VulDB User)
.