CVE-2024-2449: Progress LoadMaster
High severity, CVSS 7.5. EPSS: 12.9% chance of exploitation in the next 30 days.
A cross-site request forgery vulnerability has been identified in LoadMaster. It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site. In such a scenario, the CSRF payload hosted on the malicious site would execute HTTP transactions on behalf of the LoadMaster administrator.
Affected products
- Progress LoadMaster: from 7.2.49.0, before 7.2.54.9 (fixed in 7.2.54.9); from 7.2.55.0, before 7.2.59.3 (fixed in 7.2.59.3); version 7.1.35.10 only; version 7.2.48.10 only
Published 2024-03-22. Last modified 2026-06-17.