LOW
Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment
Published Jul 19, 2024
2.1
LOWCVSS 4.0
EPSS 0.21%
Description
Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment. NOTE: this is disputed by the Supplier because the product intentionally accepts anonymous, unauthenticated comments and thus there are fewer situations in which CSRF would be a useful attack technique. Also, the submitted comments are, by default, held for moderator review.
Affected products
No data.
- 3.0.229
-
- Version 3.0.229StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Processwire | Processwire | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-2411 Advisory
- https://gist.github.com/DefensiumDevelopers/608be4d10b016dce0566925368a8b08c#file-cve-2024-41597-md ExploitThird Party Advisory
- https://github.com/advisories/GHSA-r9vw-cjf9-xh4x Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-41597
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-2411 | Advisory | |
| https://gist.github.com/DefensiumDevelopers/608be4d10b016dce0566925368a8b08c#file-cve-2024-41597-md | ExploitThird Party Advisory | |
| https://github.com/advisories/GHSA-r9vw-cjf9-xh4x | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-41597 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 19, 2024
Updated Jul 9, 2026
Reserved Jul 18, 2024
Link CVE-2024-41597
CISA Vulnrichment
Updated Jul 24, 2024
ENISA EUVD
EUVD-2024-2411 GHSA-R9VW-CJF9-XH4X Assigner mitre
Published Jul 19, 2024
Updated Jul 9, 2026
Exploited since n/a
Link EUVD-2024-2411