CVE-2024-2449

A cross-site request forgery vulnerability has been identified in LoadMaster.  It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site. In such a scenario, the CSRF payload hosted on the malicious site would execute HTTP transactions on behalf of the LoadMaster administrator.
Configurations

No configuration.

History

21 Nov 2024, 09:09

Type Values Removed Values Added
References () https://progress.com/loadmaster - () https://progress.com/loadmaster -
References () https://support.kemptechnologies.com/hc/en-us/articles/25119767150477-LoadMaster-Security-Vulnerabilities-CVE-2024-2448-and-CVE-2024-2449 - () https://support.kemptechnologies.com/hc/en-us/articles/25119767150477-LoadMaster-Security-Vulnerabilities-CVE-2024-2448-and-CVE-2024-2449 -
Summary
  • (es) Se ha identificado una vulnerabilidad de Cross-Site Request Forgery en LoadMaster. Es posible que un actor malintencionado, que tenga conocimiento previo de la IP o el nombre de host de un LoadMaster específico, dirija a un administrador de LoadMaster autenticado a un sitio de terceros. En tal escenario, el payload CSRF alojado en el sitio malicioso ejecutaría transacciones HTTP en nombre del administrador de LoadMaster.

22 Mar 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-22 14:15

Updated : 2024-11-21 09:09


NVD link : CVE-2024-2449

Mitre link : CVE-2024-2449

CVE.ORG link : CVE-2024-2449


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)