Cross-Site Request Forgery Vulnerability in Anchor CMS
CVE-2024-29338

2.4LOW

Key Information:

Vendor

Anchor CMS

Vendor
CVE Published:
22 March 2024

What is CVE-2024-29338?

Anchor CMS version 0.12.7 is susceptible to a Cross-Site Request Forgery (CSRF) attack that allows unauthorized actions to be executed on behalf of an authenticated user. This vulnerability is specifically manifested through the endpoint /anchor/admin/categories/delete/2, enabling potential attackers to manipulate category deletions without the victim's consent. Implementing CSRF protection and user session verification is essential to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.