CVE-2024-45987
Last modified
CVE-2024-45987 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vulnerability allows an attacker to craft a malicious link that, when clicked by an authenticated user, automatically submits a vote for a specified party without the user's consent or knowledge. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vulnerability allows an attacker to craft a malicious link that, when clicked by an authenticated user, automatically submits a vote for a specified party without the user's consent or knowledge. The attack leverages the user's active session to perform the unauthorized action, compromising the integrity of the voting process.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Online Voting System Project | Online Voting System | 1.0 |
References
- https://github.com/soursec/CVEs/tree/main/CVE-2024-45987Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-45987?
How severe is CVE-2024-45987?
How do I fix CVE-2024-45987?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-45981A host header injection vulnerability in BookReviewLibrary 1…8.8
- CVE-2024-45982A host header injection vulnerability in scheduleR v0.0.18 a…8.8
- CVE-2024-45983A Cross-Site Request Forgery (CSRF) vulnerability exists in …6.3
- CVE-2024-45984A Cross Site Scripting (XSS) vulnerability in add_donor.php …4.7
- CVE-2024-45985A Cross Site Scripting (XSS) vulnerability in update_contact…4.7
- CVE-2024-45986A stored Cross-Site Scripting (XSS) vulnerability was identi…5.4
- CVE-2024-45989Monica AI Assistant desktop application v2.3.0 is vulnerable…4
- CVE-2024-4599Remote denial of service vulnerability in LAN Messenger affe…7.5
- CVE-2024-45993Giflib Project v5.2.2 is vulnerable to a heap buffer overflo…6.5
- CVE-2024-45999A SQL Injection vulnerability was discovered in Cloudlog 2.6…9.8
- CVE-2024-4600Cross-Site Request Forgery vulnerability in Socomec Net Visi…7.1
- CVE-2024-4601An incorrect authentication vulnerability has been found in …6.7
Are you affected by CVE-2024-45987?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
