Cross-Site Request Forgery Vulnerability in DedeCMS by Dede
CVE-2024-28669

5.4MEDIUM

Key Information:

Vendor

Dede

Status
Vendor
CVE Published:
13 March 2024

What is CVE-2024-28669?

DedeCMS v5.7 has been identified to have a Cross-Site Request Forgery (CSRF) vulnerability that exposes users to unauthorized actions through malicious requests sent to the application. This issue arises from improper verification of user requests, specifically through the endpoint /dede/freelist_edit.php. Attackers could exploit this vulnerability to execute unintended operations on behalf of authenticated users, potentially compromising the integrity of the web application.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.