Cross-Site Request Forgery Vulnerability in Mesmerize by Horea Radu
CVE-2024-37431
4.3MEDIUM
Summary
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Mesmerize theme developed by Horea Radu. This security flaw allows attackers to exploit the application by forging requests on behalf of authenticated users. As a result, malicious users could potentially perform unauthorized actions, leading to significant security risks for affected sites. This issue affects all versions of Mesmerize from n/a to 1.6.120, raising concerns about the integrity and safety of user interactions within the application. Site administrators are urged to apply necessary updates and security patches immediately to mitigate these risks.
Affected Version(s)
Mesmerize <= 1.6.120
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dhabaleshwar Das (Patchstack Alliance)