Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-11071


Permissive Cross-domain Policy with Untrusted Domains vulnerability in local API server of DestinyECM solution(versions described below) which is developed and maintained by Cyberdigm may allow Cross-Site Request Forgery (CSRF) attack, which probabilistically enables JSON Hijacking (aka JavaScript Hijacking) via forgery web page.* Due to product customization, version information may differ from the following version description. For further inquiries, please contact the vendor.


Published

2025-04-07T06:15:39.167

Last Modified

2025-04-07T14:17:50.220

Status

Awaiting Analysis

Source

09832df1-09c1-45b4-8a85-16c601d30feb

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-352
    CWE-942

Affected Vendors & Products

-


References