CVE-2024-37774

HIGH

Sunbird DCIM dcTrack 9.1.2 - Authenticated Privilege Escalation via Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens.

Scores

CVSS v3 8.0
EPSS 0.0019
EPSS Percentile 8.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-352
Status published
Products (1)
sunbirddcim/dctrack 9.1.2
Published Dec 16, 2024
Tracked Since Feb 18, 2026