CVE-2024-54792

MEDIUM

ENG Spagobi - CSRF

Title source: rule
STIX 2.1

Description

A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead another user into executing unwanted actions inside the application they are logged in, like adding, editing or deleting users.

Scores

CVSS v3 6.1
EPSS 0.0015
EPSS Percentile 34.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
eng/spagobi 3.5.1
Published Jan 21, 2025
Tracked Since Feb 18, 2026