Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40137
HistoryApr 17, 2023 - 1:57 p.m.

Cross-Site Request Forgery (CSRF)

2023-04-1713:57:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16
cross-site request forgery
csrf
vulnerability
sveltejs/kit
http.js
unauthorized access

EPSS

0.001

Percentile

46.2%

@sveltejs/kit is vulnerable to Cross-Site Request Forgery (CSRF). The vulnerability exists in the negotiate function of http.js due to the case-insensitive comparison when checking the header value, which allows an attacker to execute operations within the victim’s session, leading to unauthorized access to user accounts.

EPSS

0.001

Percentile

46.2%

Related for VERACODE:40137