CVE-2013-7464

CVE-2013-7464

In csrf-magic before 1.0.4, if $GLOBALS[‘csrf’][‘secret’] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, because an automatically generated secret is not used.

Source: CVE-2013-7464

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다