CVE-2024-54792 Details
Description
A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead another user into executing unwanted actions inside the application they are logged in, like adding, editing or deleting users.
A Cross-Site Request Forgery (CSRF) vulnerability exists in SpagoBI version 3.5.1, specifically within the user administration panel. This vulnerability allows an authenticated user to manipulate another user into performing unintended actions, such as adding, editing, or deleting users, while they are logged into the application.
Users are advised to update to the latest version of SpagoBI.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/MarioTesoro/CVE-2024-54792 | [email protected] | ExploitThird Party Advisory |
| https://github.com/MarioTesoro/vulnerability-research/tree/main/CVE-2024-54792 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| eng spagobi | 3.5.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 17, 2025 | CVE Modified | [email protected] |
| Jul 3, 2025 | Initial Analysis | [email protected] |
| Jan 21, 2025 | CVE Modified | CISA-ADP |
| Jan 21, 2025 | New CVE Received | [email protected] |