CVE-2024-45161
BaseFortify
Publication date: 2025-10-29
Last updated on: 2025-10-30
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| blu-castle | bcum221e | 1.0.0p220507 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-352 | The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a Cross-Site Request Forgery (CSRF) issue in the administrative web GUI of Blu-Castle BCUM221E version 1.0.0P220507. It can be exploited by tricking an authenticated user into executing unwanted actions via a crafted URL, image load, XMLHttpRequest, or similar methods, potentially leading to exposure of data or unintended code execution.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized actions being performed in the administrative interface, which may result in exposure of sensitive data or execution of unintended code. This could compromise the security and integrity of the affected system.