Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54373 | Permissive Cross-domain Policy with Untrusted Domains vulnerability in local API server of DestinyECM solution(versions described below) which is developed and maintained by Cyberdigm may allow Cross-Site Request Forgery (CSRF) attack, which probabilistically enables JSON Hijacking (aka JavaScript Hijacking) via forgery web page.* Due to product customization, version information may differ from the following version description. For further inquiries, please contact the vendor. |
| Link | Providers |
|---|---|
| https://cyberdigm.co.kr/destinyEcm |
|
Mon, 07 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Apr 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Permissive Cross-domain Policy with Untrusted Domains vulnerability in local API server of DestinyECM solution(versions described below) which is developed and maintained by Cyberdigm may allow Cross-Site Request Forgery (CSRF) attack, which probabilistically enables JSON Hijacking (aka JavaScript Hijacking) via forgery web page.* Due to product customization, version information may differ from the following version description. For further inquiries, please contact the vendor. | |
| Title | Improper Access Control In DestinyECM | |
| Weaknesses | CWE-352 CWE-942 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: FSI
Published:
Updated: 2025-04-15T00:53:10.622Z
Reserved: 2024-11-11T08:07:36.256Z
Link: CVE-2024-11071
Updated: 2025-04-07T19:35:05.652Z
Status : Deferred
Published: 2025-04-07T06:15:39.167
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-11071
No data.
OpenCVE Enrichment
No data.
EUVD