CVE-2024-28141
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedThe web application is not protected against cross-site request forgery attacks. Therefore, an attacker can trick users into performing actions on the application when they visit an attacker-controlled website or click on a malicious link. E.g. an attacker can forge malicious links to reset the admin password or create new users.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · high confidenceThe web application lacks CSRF protection, allowing attackers to forge requests that execute privileged actions (password resets, user creation) when authenticated users visit malicious sites or click attacker-controlled links.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- None
- User interaction
- Required
- Scope
- Unchanged
- Confidentiality
- Low
- Integrity
- Low
- Availability
- Low
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Inspect forms for anti-CSRF tokensExamine HTML source code of forms that perform state-changing operations (password reset, user creation, account settings). Look for hidden input fields containing random token values (e.g., <input type='hidden' name='csrf_token' value='...'> or similar). Check if these tokens are submitted with the form request.Affected if Forms handling privileged actions lack hidden CSRF token fields or tokens are not validated server-side.
-
Verify SameSite cookie configurationInspect HTTP response headers from the application. Look for Set-Cookie headers and verify if the SameSite attribute is present and set to 'Strict' or 'Lax'. Use browser DevTools (Application tab > Cookies) or capture headers via a proxy/tool like Burp Suite or curl -I.Affected if Cookies are sent without SameSite attribute or it is set to 'None' without Secure flag, allowing cross-site requests.
-
Test token validation on state-changing requestsPerform a legitimate state-changing action (e.g., submit a password change) while intercepting the request. Remove or modify any CSRF token parameter and resubmit the request. Observe if the server accepts or rejects the request.Affected if The server processes the request successfully without a valid CSRF token, indicating missing server-side validation.
-
Check for CSRF-prevention headersReview HTTP response headers for anti-CSRF protections such as 'CSRF-Token' or custom headers. Also check if the application implements double-submit cookie patterns by inspecting whether a CSRF token is expected in both cookie and request parameters.Affected if No CSRF-related headers are present and no double-submit cookie mechanism is implemented.
-
Review authentication flow for stateless CSRF protectionAnalyze the application's authentication mechanism. Check if the application relies solely on authentication (e.g., session cookies) without additional CSRF mitigations for privileged operations.Affected if State-changing actions are protected only by authentication cookies without supplementary CSRF defenses.
The environment is affected if the web application does not implement anti-CSRF tokens or SameSite cookie attributes for state-changing operations like password resets or user creation.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
From vendor dataImplement anti-CSRF tokens (synchronizer token pattern) for all state-changing operations and configure SameSite cookie attributes to prevent cross-site request forgery.
- Consultation3.0 h
- Implementation12.0 h
- Testing6.0 h
- Review / QA3.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $6,720.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2024-28141 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2024-28141 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data