Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24450
HistoryApr 10, 2020 - 12:54 a.m.

Cross-site Request Forgery (CSRF)

2020-04-1000:54:22
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

EPSS

0.004

Percentile

72.4%

firefox is vulnerable to cross-site request forgery. The vulnerability exists as a flaw was found in the way Firefox handled plug-ins that perform HTTP requests. If a plug-in performed an HTTP request, and the server sent a 307 redirect response, the plug-in was not notified, and the HTTP request was forwarded. The forwarded request could contain custom headers.