CVE-2024-51382

HIGH

JATOS 3.9.3 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the administrator's password. This critical security flaw can result in unauthorized access to the platform, enabling attackers to hijack admin accounts and compromise the integrity and security of the system.

References (1)

Core 1

Scores

CVSS v3 8.4
EPSS 0.0023
EPSS Percentile 13.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-352
Status published
Products (1)
jatos/jatos 3.9.3
Published Nov 05, 2024
Tracked Since Feb 18, 2026