Web App Vulnerable to Cross-Site Request Forgery Attacks
CVE-2024-28141

Currently unrated

Key Information:

Status
Vendor
CVE Published:
11 December 2024

What is CVE-2024-28141?

The web application is not protected against cross-site request forgery attacks. Therefore, an attacker can trick users into performing actions on the application when they visit an attacker-controlled website or click on a malicious link. E.g. an attacker can forge malicious links to reset the admin password or create new users.

Affected Version(s)

Scan2Net 0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniel Hirschberger (SEC Consult Vulnerability Lab)
Tobias Niemann (SEC Consult Vulnerability Lab)
.