CVE-2024-5676
CVSS V2 None
CVSS V3 None
Description
The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a lack of countermeasures and the use of the HTTP method `GET` to introduce changes in the system.
Overview
- CVE ID
- CVE-2024-5676
- Assigner
- sba-research
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-06-19T09:47:38.961Z
- Last Modified Date
- 2024-06-19T09:47:38.961Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/sbaresearch/advisories/tree/public/2024/SBA-ADV-20240321-01_Paradox_Cross_Site_Request_Forgery | third-party-advisory |
https://www.paradox.com/Products/default.asp?CATID=3&SUBCATID=38&PRD=563 | product |
http://seclists.org/fulldisclosure/2024/Jun/8 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-5676 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5676 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 03:07:33 | Added to TrackCVE |