Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38346
HistoryDec 06, 2022 - 2:27 a.m.

Cross-Site Request Forgery (CSRF)

2022-12-0602:27:24
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
cross-site request forgery
csrf
request.php
craftcms
password hash disclosure

0.002 Low

EPSS

Percentile

53.7%

craftcms/cms is vulnerable to cross-site request forgery. The vulnerability exists because the CRAFT_CSRF_TOKEN cookie in Request.php gets improperly encoded, allowing an attacker to disclose the password hash through the HTML hidden field.

CPENameOperatorVersion
craftcms/cmsle3.7.32
craftcms/cmsle3.7.32

0.002 Low

EPSS

Percentile

53.7%

Related for VERACODE:38346