A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens.
                
            Metrics
Affected Vendors & Products
References
        History
                    Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Fri, 20 Jun 2025 18:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Sunbirddcim Sunbirddcim dctrack | |
| CPEs | cpe:2.3:a:sunbirddcim:dctrack:9.1.2:*:*:*:*:*:*:* | |
| Vendors & Products | Sunbirddcim Sunbirddcim dctrack | 
Tue, 17 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-352 | |
| Metrics | cvssV3_1 
 
 | 
Mon, 16 Dec 2024 21:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens. | |
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2024-12-16T00:00:00
Updated: 2024-12-17T15:06:07.944Z
Reserved: 2024-06-10T00:00:00
Link: CVE-2024-37774
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-12-17T15:05:30.806Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-12-16T22:15:06.127
Modified: 2025-06-20T18:15:42.100
Link: CVE-2024-37774
 Redhat
                        Redhat
                    No data.