CVE-2024-45987

Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vulnerability allows an attacker to craft a malicious link that, when clicked by an authenticated user, automatically submits a vote for a specified party without the user's consent or knowledge. The attack leverages the user's active session to perform the unauthorized action, compromising the integrity of the voting process.
References
Link Resource
https://github.com/soursec/CVEs/tree/main/CVE-2024-45987 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:online_voting_system_project:online_voting_system:1.0:*:*:*:*:*:*:*

History

05 Oct 2024, 02:21

Type Values Removed Values Added
First Time Online Voting System Project
Online Voting System Project online Voting System
References () https://github.com/soursec/CVEs/tree/main/CVE-2024-45987 - () https://github.com/soursec/CVEs/tree/main/CVE-2024-45987 - Exploit, Third Party Advisory
CPE cpe:2.3:a:online_voting_system_project:online_voting_system:1.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-352

30 Sep 2024, 12:46

Type Values Removed Values Added
Summary
  • (es) Projectworld Online Voting System Version 1.0 es vulnerable a Cross Site Request Forgery (CSRF) a través de voter.php. Esta vulnerabilidad permite a un atacante crear un vínculo malicioso que, cuando un usuario autenticado hace clic en él, envía automáticamente un voto para un partido específico sin el consentimiento o conocimiento del usuario. El ataque aprovecha la sesión activa del usuario para realizar la acción no autorizada, lo que compromete la integridad del proceso de votación.

26 Sep 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-26 18:15

Updated : 2024-10-05 02:21


NVD link : CVE-2024-45987

Mitre link : CVE-2024-45987

CVE.ORG link : CVE-2024-45987


JSON object : View

Products Affected

online_voting_system_project

  • online_voting_system
CWE
CWE-352

Cross-Site Request Forgery (CSRF)