Home

Description

Permissive Cross-domain Policy with Untrusted Domains vulnerability in local API server of DestinyECM solution(versions described below) which is developed and maintained by Cyberdigm may allow Cross-Site Request Forgery (CSRF) attack, which probabilistically enables JSON Hijacking (aka JavaScript Hijacking) via forgery web page.* Due to product customization, version information may differ from the following version description. For further inquiries, please contact the vendor.

PUBLISHED Reserved 2024-11-11 | Published 2025-04-07 | Updated 2025-04-15 | Assigner FSI




HIGH: 7.7CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N

HIGH: 8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Problem types

CWE-352 Cross-Site Request Forgery (CSRF)

CWE-942 Permissive Cross-domain Policy with Untrusted Domains

Product status

Default status
unaffected

5.24.10.* (custom) before 5.24.10.2303
affected

5.23.10.* (custom) before 5.23.12.2450
affected

5.23.02.* (custom) before 5.23.08.2451
affected

5.22.* (custom) before 5.22.12.2446
affected

5.21.*, 5.20.*, 5.19.* (custom) before 5.21.12.2303
affected

Credits

jskimpwn(김지섭, Jisub Kim) finder

arang(유재욱, Jaewook You) finder

References

cyberdigm.co.kr/destinyEcm

cve.org (CVE-2024-11071)

nvd.nist.gov (CVE-2024-11071)

Download JSON