CVE-2024-2449
A cross-site request forgery vulnerability has been identified in LoadMaster. It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site. In such a scenario, the CSRF payload hosted on the malicious site would execute HTTP transactions on behalf of the LoadMaster administrator.
- Affected products
- Loadmaster
- Progress Loadmaster
- < 7.2.54.9, 7.2.59.3, 7.1.35.10, 7.2.48.10
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 12.9% (96th percentile)
- Weakness
- CWE-352
- NVD status
- Analyzed
- Published
- 2024-03-22
- Attack patterns
- CAPEC-62
CVE-2024-2449 at NVD
1 known exploit for CVE-2024-2449
Proof-of-concept code and exploit modules indexed by Sploitus