CVE-2024-56903

Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against critical functionalities, such as account management. This vulnerability is used in chain with CVE-2024-56901 for a successful CSRF attack.
Configurations

No configuration.

History

04 Mar 2025, 22:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CWE CWE-352

03 Mar 2025, 22:15

Type Values Removed Values Added
Summary (en) A Cross-Site Request Forgery (CSRF) in Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to execute arbitrary operations via supplying a crafted HTTP request. (en) Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against critical functionalities, such as account management. This vulnerability is used in chain with CVE-2024-56901 for a successful CSRF attack.

18 Feb 2025, 19:15

Type Values Removed Values Added
CWE CWE-352
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : unknown

04 Feb 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-352
Summary
  • (es) Cross-Site Request Forgery (CSRF) en Geovision GV-ASWeb con la versión 6.1.1.0 o menos permite a los atacantes ejecutar operaciones arbitrarias mediante el suministro de una solicitud HTTP manipulado.

03 Feb 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-03 21:15

Updated : 2025-03-04 22:15


NVD link : CVE-2024-56903

Mitre link : CVE-2024-56903

CVE.ORG link : CVE-2024-56903


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)