CVE-2024-11071: Cyberdigm Destinyecm
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Permissive Cross-domain Policy with Untrusted Domains vulnerability in local API server of DestinyECM solution(versions described below) which is developed and maintained by Cyberdigm may allow Cross-Site Request Forgery (CSRF) attack, which probabilistically enables JSON Hijacking (aka JavaScript Hijacking) via forgery web page.* Due to product customization, version information may differ from the following version description. For further inquiries, please contact the vendor.
Affected products
- Cyberdigm Destinyecm: from 5.24.10, before 5.24.10.2303 (fixed in 5.24.10.2303); from 5.23.10, before 5.23.12.2450 (fixed in 5.23.12.2450); from 5.23.02, before 5.23.08.2451 (fixed in 5.23.08.2451); from 5.22, before 5.22.12.2446 (fixed in 5.22.12.2446)
Published 2025-04-07. Last modified 2026-06-17.