CVE-2024-40488

A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the administrator into deleting valid member data via a crafted HTML page, as demonstrated by a Delete Member action at the /delete_members.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lopalopa:live_membership_system:1.0:*:*:*:*:*:*:*

History

28 Apr 2025, 14:24

Type Values Removed Values Added
References () https://capec.mitre.org/data/definitions/62.html - () https://capec.mitre.org/data/definitions/62.html - Third Party Advisory
References () https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Live%20Membership%20System%20v1.0/CSRF.pdf - () https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Live%20Membership%20System%20v1.0/CSRF.pdf - Exploit, Third Party Advisory
Summary
  • (es) Se encontró una vulnerabilidad de Cross-Site Request Forgery (CSRF) en Kashipara Live Membership System v1.0. Esto podría llevar a que un atacante engañe al administrador para que elimine datos válidos de los miembros a través de una página HTML manipulada, como lo demuestra la acción Eliminar miembro en /delete_members.php.
First Time Lopalopa
Lopalopa live Membership System
CPE cpe:2.3:a:lopalopa:live_membership_system:1.0:*:*:*:*:*:*:*

13 Aug 2024, 01:13

Type Values Removed Values Added
CWE CWE-352
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

12 Aug 2024, 13:41

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-12 13:38

Updated : 2025-04-28 14:24


NVD link : CVE-2024-40488

Mitre link : CVE-2024-40488

CVE.ORG link : CVE-2024-40488


JSON object : View

Products Affected

lopalopa

  • live_membership_system
CWE
CWE-352

Cross-Site Request Forgery (CSRF)