Vulnerability Description
Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can lead to unauthorized activities, compromising the security and integrity of the platform, especially if an attacker gains administrative control.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jatos | Jatos | 3.9.3 |
Related Weaknesses (CWE)
References
- https://hacking-notes.medium.com/cve-2024-51381-jatos-v3-9-3-csrf-admin-account-ExploitThird Party Advisory
FAQ
What is CVE-2024-51381?
CVE-2024-51381 is a vulnerability with a CVSS score of 8.4 (HIGH). Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can lead to ...
How severe is CVE-2024-51381?
CVE-2024-51381 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-51381?
Check the references section above for vendor advisories and patch information. Affected products include: Jatos Jatos.