ZeroHour

CVE-2024-37774

CVSS 3.1
8.0 high
EPSS
<1%p9
Published
()
Modified
Description

A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens.

Vendors
sunbirddcim
Products
dctrack
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.