CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-6880: CSRF in MegaBIP

6.9 CVSS

Description

During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping it secret is listed by the author as one of the protection mechanisms. 
Publicly available source code of "/registered.php" discloses that path, allowing an attacker to attempt further attacks.  

This issue affects MegaBIP software versions below 5.15

Classification

CVE ID: CVE-2024-6880

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.9

Affected Products

Vendor: Jan Syski

Product: MegaBIP

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 17.82% (scored less or equal to compared to others)

EPSS Date: 2025-02-08 (when was this score calculated)

References

https://cert.pl/en/posts/2024/09/CVE-2024-6680
https://megabip.pl/
https://www.gov.pl/web/cyfryzacja/rekomendacja-pelnomocnika-rzadu-ds-cyberbezpieczenstwa-dotyczaca-biuletynow-informacji-publicznej

Timeline