CVE-2024-57373

HIGH

LifestyleStore 1.0 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-57373. PoCs published by cypherdavy.

AI-analyzed exploit summary This repository documents a CSRF vulnerability in LifestyleStore v1.0, detailing its impact, technical mechanics, and mitigation strategies. It does not contain exploit code but provides a clear explanation of the flaw.

Description

Cross Site Request Forgery (CSRF) vulnerability in LifestyleStore v1.0 allows a remote attacker to execute unauthorized actions on behalf of an authenticated user, potentially leading to account modifications or data compromise.

Exploits (1)

nomisec WRITEUP 3 stars
by cypherdavy · poc
https://github.com/cypherdavy/CVE-2024-57373

This repository documents a CSRF vulnerability in LifestyleStore v1.0, detailing its impact, technical mechanics, and mitigation strategies. It does not contain exploit code but provides a clear explanation of the flaw.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: LifestyleStore v1.0
Auth required
Prerequisites: Authenticated user session · Victim interaction (e.g., clicking a malicious link)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 8.1
EPSS 0.0036
EPSS Percentile 27.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-352
Status published
Published Jan 27, 2025
Tracked Since Feb 18, 2026