CVE-2024-5676

Published Jun 19, 2024

Last updated 5 months ago

Overview

Description
The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a lack of countermeasures and the use of the HTTP method `GET` to introduce changes in the system.
Source
1e3a9e0f-5156-4bf8-b8a3-cc311bfc0f4a
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.8
Impact score
5.2
Exploitability score
1.6
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
Severity
MEDIUM

Weaknesses

1e3a9e0f-5156-4bf8-b8a3-cc311bfc0f4a
CWE-352

Social media

Hype score
Not currently trending