CVE-2024-2449

HIGH

LoadMaster 7.2.49.0-7.2.54.8 and 7.2.55.0-7.2.59.2 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

A cross-site request forgery vulnerability has been identified in LoadMaster.  It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site. In such a scenario, the CSRF payload hosted on the malicious site would execute HTTP transactions on behalf of the LoadMaster administrator.

Scores

CVSS v3 7.5
EPSS 0.0332
EPSS Percentile 87.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-352
Status published
Products (4)
progress/loadmaster 7.1.35.10
progress/loadmaster 7.2.48.10
progress/loadmaster 7.2.49.0 - 7.2.54.9
progress/loadmaster 7.2.55.0 - 7.2.59.3
Published Mar 22, 2024
Tracked Since Feb 18, 2026