Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7630
HistoryOct 22, 2018 - 9:32 a.m.

Cross-Site Request Forgery (CSRF)

2018-10-2209:32:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

EPSS

0.001

Percentile

50.4%

tribalsystems/zenario is vulnerable to cross-site request forgery (CSRF). The application does not verify the authenticity of a request to admin/organizer.ajax.php?path=zenario__content%2Fpanels%2Fcontent, which allows an attacker to submit a request on behalf of the victim when the victim visits a malicious HTML page.

EPSS

0.001

Percentile

50.4%