{"id":"CVE-2024-53684","details":"A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious webpage to trigger this vulnerability.","modified":"2026-03-15T14:51:38.273046Z","published":"2025-12-01T16:15:50.513Z","references":[{"type":"ADVISORY","url":"https://talosintelligence.com/vulnerability_reports/TALOS-2024-2116"},{"type":"ADVISORY","url":"https://www.socomec.fr/sites/default/files/2025-10/CVE-2024-53684---Diris-Digiware-Mxx-Dxx-_VULNERABILITIES_2025-10-01-16-43-14_English_0.pdf"},{"type":"ADVISORY","url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2116"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"1.6.9"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-53684.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}