VYPR
Unrated severityNVD Advisory· Published Feb 11, 2024· Updated May 15, 2025

CVE-2024-25419

CVE-2024-25419

Description

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_menu.php.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A CSRF vulnerability in flusity-CMS v2.33 allows an attacker to update menu entries via the `/core/tools/update_menu.php` endpoint without proper token validation.

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in flusity-CMS version v2.33. The flaw is located in the /core/tools/update_menu.php component, which handles menu updates without validating a CSRF token or ensuring the request originates from the same site [1]. No authentication check is mentioned for the action, allowing state-changing requests to be forged.

Exploitation

An attacker can craft a malicious HTML page that automatically submits a POST request to /core/tools/update_menu.php when visited by an authenticated victim. The public proof-of-concept [1] sends parameters such as menu_id, menu_name, lang_menu_name, page_url, position, template, show_in_menu, and parent_id to modify an existing menu item. The only requirement is that the victim must be logged into flusity-CMS [1]. The request is submitted via a form with action set to the vulnerable endpoint, using no additional headers or tokens.

Impact

Successful exploitation allows an attacker to modify menu entries in the CMS, potentially changing navigation or redirecting users to malicious pages. The impact is limited to menu configuration changes; the attacker does not gain direct code execution or privilege escalation from this CSRF alone. However, combined with other vulnerabilities, it could facilitate deeper attacks such as stored XSS via menu names or URLs.

Mitigation

As of the publication date (2024-02-11) and based on the reference [1], no official patch has been released for flusity-CMS v2.33. The vendor has not provided a fixed version or workaround. Sites using this version should consider implementing custom CSRF protections, such as adding anti-CSRF tokens to all state-changing forms and verifying the Origin or Referer header. If the CMS is unmaintained, migrating to an alternative solution is recommended.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.