Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37512
HistoryOct 11, 2022 - 2:13 p.m.

Cross-site Request Forgery (CSRF)

2022-10-1114:13:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
cross-site request forgery
csrf vulnerability
cookie encryption
token access

EPSS

0.001

Percentile

48.7%

tiny-csrf is vulnerable to cross-site request forgery. The vulnerability exists due tocsurf because the cookies are not encrypted which allows an attacker to gain access to the tokens and bypass CSRF checks.

EPSS

0.001

Percentile

48.7%

Related for VERACODE:37512