CVE-2024-9282

Source
https://cve.org/CVERecord?id=CVE-2024-9282
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-9282.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-9282
Published
2024-09-27T13:15:18.443Z
Modified
2025-11-16T12:09:21.815757Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

A vulnerability was found in bg5sbk MiniCMS 1.11. It has been classified as problematic. Affected is an unknown function of the file page-edit.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions confusing version and file name information. The vendor was contacted early about this disclosure but did not respond in any way.

References

Affected packages

Git / github.com/bg5sbk/minicms

Affected ranges

Type
GIT
Repo
https://github.com/bg5sbk/minicms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*
1.6
v1.*
v1.0
v1.1
v1.10
v1.2
v1.3
v1.4
v1.5
v1.7
v1.8
v1.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-9282.json"