CVE-2024-38457
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.8epss 7.4%
exploitation probability
7.4%top 6% of all CVEs
observed exploitation
nono source reports it
In short
XenForo before version 2.2.16 is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to trick users into performing unwanted actions on the forum without their knowledge.
Technical detail
This CSRF vulnerability (CWE-352) in XenForo prior to 2.2.16 enables an attacker to forge requests on behalf of authenticated users by embedding malicious actions in external web pages; exploitation requires user interaction (visiting a crafted page while logged in) and can result in unauthorized modifications to forum data or account settings.
Summary generated and translated by AI from the official description.
Xenforo before 2.2.16 allows CSRF.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a