A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens.
References
Link | Resource |
---|---|
http://dctrack.com | Product |
https://s3.us-east-1.amazonaws.com/dcTrack.Docs/dcTrack_9.2.0_GA/dcTrack_9.2.0_Release_Notes.pdf | Release Notes |
Configurations
History
20 Jun 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
First Time |
Sunbirddcim
Sunbirddcim dctrack |
|
References | () http://dctrack.com - Product | |
References | () https://s3.us-east-1.amazonaws.com/dcTrack.Docs/dcTrack_9.2.0_GA/dcTrack_9.2.0_Release_Notes.pdf - Release Notes | |
CPE | cpe:2.3:a:sunbirddcim:dctrack:9.1.2:*:*:*:*:*:*:* |
17 Dec 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-16 22:15
Updated : 2025-06-20 18:15
NVD link : CVE-2024-37774
Mitre link : CVE-2024-37774
CVE.ORG link : CVE-2024-37774
JSON object : View
Products Affected
sunbirddcim
- dctrack
CWE
CWE-352
Cross-Site Request Forgery (CSRF)