Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:47262
HistoryMay 30, 2024 - 6:05 a.m.

Cross-site Request Forgery (CSRF)

2024-05-3006:05:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
3
cross-site request forgery
csrf
sylius/resource-bundle
adminbundle
resourcebundle
unauthorized actions

AI Score

7

Confidence

Low

sylius/resource-bundle is vulnerable to a Cross-Site Request Forgery. The vulnerability is due to the absence of proper validation and insufficient CSRF protection for actions such as marking order payments or product reviews in the AdminBundle and ResourceBundle. This allowing attackers to perform unauthorized actions on behalf of authenticated users.

AI Score

7

Confidence

Low