A Cross-Site Request Forgery (CSRF) vulnerability was identified in the stitionai/devika application, affecting the latest version. This vulnerability allows attackers to perform unauthorized actions in the context of a victim's browser, such as deleting projects or changing application settings, without any CSRF protection implemented. Successful exploitation disrupts the integrity and availability of the application and its data.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://huntr.com/bounties/301aeafb-af28-4b0b-a2cf-9a2ff1da1ef4 | Exploit Third Party Advisory |
https://huntr.com/bounties/301aeafb-af28-4b0b-a2cf-9a2ff1da1ef4 | Exploit Third Party Advisory |
Configurations
History
15 Jul 2025, 13:25
Type | Values Removed | Values Added |
---|---|---|
References | () https://huntr.com/bounties/301aeafb-af28-4b0b-a2cf-9a2ff1da1ef4 - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:stitionai:devika:1.0:*:*:*:*:*:*:* | |
CWE | ||
First Time |
Stitionai devika
Stitionai |
12 Jul 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
Summary | A Cross-Site Request Forgery (CSRF) vulnerability was identified in the stitionai/devika application, affecting the latest version. This vulnerability allows attackers to perform unauthorized actions in the context of a victim's browser, such as deleting projects or changing application settings, without any CSRF protection implemented. Successful exploitation disrupts the integrity and availability of the application and its data. |
28 Jun 2024, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-28 20:15
Updated : 2025-07-15 13:25
NVD link : CVE-2024-5712
Mitre link : CVE-2024-5712
JSON object : View
Products Affected
stitionai
- devika
CWE
No CWE.