
Cloud Vulnerability DB
A community-led vulnerabilities database
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Spina CMS version 2.18.0, specifically affecting the functionality of the file /admin/media_folders. The vulnerability was assigned CVE-2024-7106 and was publicly disclosed with the identifier VDB-272431. The vendor was contacted about this disclosure but did not respond (VulDB Entry).
The vulnerability is classified as a Cross-Site Request Forgery (CSRF) issue (CWE-352) that can be exploited remotely. According to the CVSS 3.1 scoring, it has received a base score of 8.8 HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) from NIST NVD, while VulDB assessed it with a more moderate score of 4.3 MEDIUM (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N) (NVD).
The vulnerability allows attackers to perform unauthorized actions through CSRF attacks against the admin media folders functionality. The high CVSS score indicates potential for significant impact on confidentiality, integrity, and availability of the affected system if exploited (NVD).
The vulnerability can be exploited remotely and requires user interaction. A proof of concept exploit has been publicly disclosed using JavaScript code that manipulates the browser history state and submits a form: 'history.pushState('', '', '/'); document.forms[0].submit();' (Security Collections).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."