A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Jun 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sunbirddcim
Sunbirddcim dctrack |
|
CPEs | cpe:2.3:a:sunbirddcim:dctrack:9.1.2:*:*:*:*:*:*:* | |
Vendors & Products |
Sunbirddcim
Sunbirddcim dctrack |
Tue, 17 Dec 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-352 | |
Metrics |
cvssV3_1
|
Mon, 16 Dec 2024 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-12-16T00:00:00
Updated: 2024-12-17T15:06:07.944Z
Reserved: 2024-06-10T00:00:00
Link: CVE-2024-37774

Updated: 2024-12-17T15:05:30.806Z

Status : Analyzed
Published: 2024-12-16T22:15:06.127
Modified: 2025-06-20T18:15:42.100
Link: CVE-2024-37774

No data.