Cross-Site Request Forgery Vulnerability in Kashipara Music Management System
CVE-2024-42791
8.8HIGH
What is CVE-2024-42791?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Kashipara Music Management System v1.0, specifically through the endpoint /music/ajax.php?action=delete_genre. This flaw allows an attacker to exploit the system by tricking a logged-in user into initiating a delete genre action without their consent. As a result, unauthorized actions could be executed within the application, potentially leading to loss of data or disruption of service. Proper validation and CSRF token implementation are essential to mitigate such risks.
