CVE-2024-41987

The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
CVSS

No CVSS.

Configurations

No configuration.

History

04 Oct 2024, 13:50

Type Values Removed Values Added
Summary
  • (es) La interfaz de la aplicación TEM Opera Plus FM Family Transmitter permite a los usuarios realizar determinadas acciones a través de solicitudes HTTP sin realizar ninguna comprobación de validez para verificar las solicitudes. Esto se puede aprovechar para realizar determinadas acciones con privilegios administrativos si un usuario conectado visita un sitio web malicioso.

03 Oct 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-03 18:15

Updated : 2024-10-04 13:50


NVD link : CVE-2024-41987

Mitre link : CVE-2024-41987

CVE.ORG link : CVE-2024-41987


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)