Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-90853
HistoryNov 22, 2021 - 12:00 a.m.

Solidus Cross-Site Request Forgery Vulnerability

2021-11-2200:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
solidus
e-commerce
csrf
vulnerability
authentication

EPSS

0.001

Percentile

47.1%

Solidus is an open source e-commerce system. A cross-site request forgery vulnerability exists in Solidus Solidus_auth_devise, which stems from a lack of CSRF authentication in the product. An attacker could send an unintended request to the server through this vulnerability.

EPSS

0.001

Percentile

47.1%