CVE-2024-31360
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 12, 2024
Updated: Apr 15, 2024
CWE ID 352
Summary
CVE-2024-31360 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Benchmark Email Lite suite from Coded Commerce, LLC. This issue allows an attacker to force a user to perform unwanted actions within the application, potentially leading to unauthorized changes or information disclosure. The flaw impacts all versions of Benchmark Email Lite from the earliest release through 4.1. To mitigate this risk, users are advised to update to the latest available version and implement appropriate CSRF tokens to secure their requests.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share