← back
CVE-2024-38457highCWE-352

CVE-2024-38457

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 7.4%
exploitation probability
7.4%top 6% of all CVEs
observed exploitation
nono source reports it
In short

XenForo before version 2.2.16 is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to trick users into performing unwanted actions on the forum without their knowledge.

Technical detail

This CSRF vulnerability (CWE-352) in XenForo prior to 2.2.16 enables an attacker to forge requests on behalf of authenticated users by embedding malicious actions in external web pages; exploitation requires user interaction (visiting a crafted page while logged in) and can result in unauthorized modifications to forum data or account settings.

Summary generated and translated by AI from the official description.
Xenforo before 2.2.16 allows CSRF.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a