Beveiligingsadvies

CVE-2019-13594

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-07-14 16:19:21
Laatst bijgewerkt 2024-08-04 23:57:39
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be accepted by the server.