Cross-Site Request Forgery Vulnerability in Taggbox by Taggbox
CVE-2024-38754
4.3MEDIUM
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in Taggbox, allowing unauthorized commands to be transmitted from a user that the web application trusts. This vulnerability poses significant risks as it could enable attackers to perform malicious actions without the user's consent or knowledge, affecting the integrity and security of the application. The issue specifically impacts versions of Taggbox starting from n/a through 3.3.
Affected Version(s)
Taggbox <= 3.3
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Majed Refaea (Patchstack Alliance)