Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can lead to unauthorized activities, compromising the security and integrity of the platform, especially if an attacker gains administrative control.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 24 Jun 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:jatos:jatos:3.9.3:*:*:*:*:*:*:* |
Wed, 06 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jatos
Jatos jatos |
|
Weaknesses | CWE-352 | |
CPEs | cpe:2.3:a:jatos:jatos:*:*:*:*:*:*:*:* | |
Vendors & Products |
Jatos
Jatos jatos |
|
Metrics |
cvssV3_1
|
Tue, 05 Nov 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can lead to unauthorized activities, compromising the security and integrity of the platform, especially if an attacker gains administrative control. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-11-05T00:00:00
Updated: 2024-11-06T16:50:31.100Z
Reserved: 2024-10-28T00:00:00
Link: CVE-2024-51381

Updated: 2024-11-06T16:50:26.168Z

Status : Analyzed
Published: 2024-11-05T19:15:07.550
Modified: 2025-06-24T13:20:52.710
Link: CVE-2024-51381

No data.