CVE-2019-17590

CVE-2019-17590

The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it allows one to tamper with the csrf token values. A remote attacker can exploit this by crafting a malicious page and dispersing it to a victim via social engineering, enticing them to click the link. Once the user/victim clicks the "try again" button, the attacker can take over the account and perform unintended actions on the victim’s behalf.

Source: CVE-2019-17590

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다