Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30406
HistoryMay 10, 2021 - 8:40 a.m.

Cross-site Request Forgery (CSRF)

2021-05-1008:40:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
cross-site request forgery
software vulnerability
authentication hijack
malicious javascript
frontend navigation

EPSS

0.001

Percentile

37.8%

forkcms is vulnerable to cross-site request forgery. An attacker is able to hijack the authentication of logged administrators by injecting malicious javascript via the frontend navigation.

EPSS

0.001

Percentile

37.8%

Related for VERACODE:30406