Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w973-rg33-v5p7

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, because an automatically generated secret is not used.

In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, because an automatically generated secret is not used.

EPSS

Процентиль: 41%
0.00189
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, because an automatically generated secret is not used.

CVSS3: 8.8
nvd
больше 7 лет назад

In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, because an automatically generated secret is not used.

CVSS3: 8.8
debian
больше 7 лет назад

In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not confi ...

EPSS

Процентиль: 41%
0.00189
Низкий

8.8 High

CVSS3

Дефекты

CWE-352