CVE-2024-56903

Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against critical functionalities, such as account management. This vulnerability is used in chain with CVE-2024-56901 for a successful CSRF attack.
Configurations

No configuration.

History

No history.

Information

Published : 2025-02-03 21:15

Updated : 2025-03-04 22:15


NVD link : CVE-2024-56903

Mitre link : CVE-2024-56903

CVE.ORG link : CVE-2024-56903


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)