Medium severity4.2NVD Advisory· Published Jul 19, 2024· Updated Jul 9, 2026
CVE-2024-41597
CVE-2024-41597
Description
Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment. NOTE: this is disputed by the Supplier because the product intentionally accepts anonymous, unauthenticated comments and thus there are fewer situations in which CSRF would be a useful attack technique. Also, the submitted comments are, by default, held for moderator review.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
processwire/processwirePackagist | <= 3.0.229 | — |
Affected products
3- cpe:2.3:a:processwire:processwire:3.0.229:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- gist.github.com/DefensiumDevelopers/608be4d10b016dce0566925368a8b08cnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-r9vw-cjf9-xh4xghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-41597ghsaADVISORY
News mentions
0No linked articles in our index yet.