CVE-2024-54792

MEDIUM

SpagoBI 3.5.1 - Authenticated Cross-Site Request Forgery in User Administration Panel

Title source: llm
STIX 2.1

Description

A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead another user into executing unwanted actions inside the application they are logged in, like adding, editing or deleting users.

Scores

CVSS v3 6.1
EPSS 0.0027
EPSS Percentile 18.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
eng/spagobi 3.5.1
Published Jan 21, 2025
Tracked Since Feb 18, 2026