Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can lead to unauthorized activities, compromising the security and integrity of the platform, especially if an attacker gains administrative control.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 24 Jun 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:jatos:jatos:3.9.3:*:*:*:*:*:*:* |
Wed, 06 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jatos
Jatos jatos |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:jatos:jatos:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jatos
Jatos jatos |
|
| Metrics |
cvssV3_1
|
Tue, 05 Nov 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can lead to unauthorized activities, compromising the security and integrity of the platform, especially if an attacker gains administrative control. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-11-05T00:00:00
Updated: 2024-11-06T16:50:31.100Z
Reserved: 2024-10-28T00:00:00
Link: CVE-2024-51381
Updated: 2024-11-06T16:50:26.168Z
Status : Analyzed
Published: 2024-11-05T19:15:07.550
Modified: 2025-06-24T13:20:52.710
Link: CVE-2024-51381
No data.