CVE-2024-39063

Lime Survey <= 6.5.12 is vulnerable to Cross Site Request Forgery (CSRF). The YII_CSRF_TOKEN is only checked when passed in the body of POST requests, but the same check isn't performed in the equivalent GET requests.
Configurations

No configuration.

History

21 Nov 2024, 09:27

Type Values Removed Values Added
References () https://github.com/sysentr0py/CVEs/tree/main/CVE-2024-39063 - () https://github.com/sysentr0py/CVEs/tree/main/CVE-2024-39063 -

01 Aug 2024, 13:55

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-352

11 Jul 2024, 13:06

Type Values Removed Values Added
Summary
  • (es) Lime Survey &lt;= 6.5.12 es vulnerable a Cross Site Request Forgery (CSRF). YII_CSRF_TOKEN solo se verifica cuando se pasa en el cuerpo de las solicitudes POST, pero no se realiza la misma verificación en las solicitudes GET equivalentes.

09 Jul 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 20:15

Updated : 2024-11-21 09:27


NVD link : CVE-2024-39063

Mitre link : CVE-2024-39063

CVE.ORG link : CVE-2024-39063


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)