Products
Totara LMS
- 18.0.1
Totara LMS
- 18.0.1 Build 20231128.01
Source
cna@vuldb.com
Tags
CVE-2024-3932 details
Last Modified : April 18, 2024, 1:04 p.m.
Description
A vulnerability classified as problematic has been found in Totara LMS 18.0.1 Build 20231128.01. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-261369 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score
1 | 2 | 3 | 4.3 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|
CVSS Data
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Base Score
4.3
Exploitability Score
Impact Score
Base Severity
MEDIUM
Vector String : CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
References
URL | Source |
---|---|
https://vuldb.com/?ctiid.261369 | cna@vuldb.com |
https://vuldb.com/?id.261369 | cna@vuldb.com |
https://vuldb.com/?submit.314381 | cna@vuldb.com |