Cross-Site Request Forgery Vulnerability in Anchor CMS
CVE-2024-29338
2.4LOW
What is CVE-2024-29338?
Anchor CMS version 0.12.7 is susceptible to a Cross-Site Request Forgery (CSRF) attack that allows unauthorized actions to be executed on behalf of an authenticated user. This vulnerability is specifically manifested through the endpoint /anchor/admin/categories/delete/2, enabling potential attackers to manipulate category deletions without the victim's consent. Implementing CSRF protection and user session verification is essential to mitigate the risks associated with this vulnerability.
