Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12413
HistoryJan 15, 2019 - 9:16 a.m.

CSRF Bypass

2019-01-1509:16:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.001 Low

EPSS

Percentile

38.3%

cfme is vulnerable to CSRF bypass attacks. The vulnerability exists as a number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via GET requests instead of just POST requests. This could allow an attacker to bypass the protect_from_forgery CSRF protection causing the routes to be used. This attack would require additional cross-site scripting or similar attacks in order to execute.

References

0.001 Low

EPSS

Percentile

38.3%

Related for VERACODE:12413