CVE-2024-2449

HIGH

LoadMaster - CSRF

Title source: llm

Description

A cross-site request forgery vulnerability has been identified in LoadMaster.  It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site. In such a scenario, the CSRF payload hosted on the malicious site would execute HTTP transactions on behalf of the LoadMaster administrator.

Scores

CVSS v3 7.5
EPSS 0.0640
EPSS Percentile 90.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-352
Status published

Affected Products (4)

progress/loadmaster < 7.2.54.9
progress/loadmaster < 7.2.59.3
progress/loadmaster
progress/loadmaster

Timeline

Published Mar 22, 2024
Tracked Since Feb 18, 2026