CVE-2024-3142

A vulnerability was found in Clavister E10 and E80 up to 14.00.10 and classified as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 14.00.11 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-258917 was assigned to this vulnerability.
Configurations

No configuration.

History

04 Apr 2024, 13:15

Type Values Removed Values Added
References
  • () https://my.clavister.com/downloads/?sid=1 -

03 Apr 2024, 11:15

Type Values Removed Values Added
References
  • () https://docs.clavister.com/repo/cos-core-release-notes/doc/index.html#d0e2260 -
Summary (en) A vulnerability was found in Clavister E10 and E80 up to 20240323 and classified as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258917 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. (en) A vulnerability was found in Clavister E10 and E80 up to 14.00.10 and classified as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 14.00.11 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-258917 was assigned to this vulnerability.

02 Apr 2024, 12:50

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en Clavister E10 y E80 hasta 20240323 y se clasificó como problemática. Este problema afecta un procesamiento desconocido del componente Controlador de configuración. La manipulación conduce a cross-site request forgery. El ataque puede iniciarse de forma remota. El exploit ha sido divulgado al público y puede utilizarse. A esta vulnerabilidad se le asignó el identificador VDB-258917. NOTA: Se contactó primeramente con el proveedor sobre esta divulgación, pero no respondió de ninguna manera.

02 Apr 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-02 01:15

Updated : 2024-05-17 02:39


NVD link : CVE-2024-3142

Mitre link : CVE-2024-3142

CVE.ORG link : CVE-2024-3142


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)