get-request-misuse

1 article
sort: new top best
clear filter
0 6/10

CVE-2017-5244 is a CSRF vulnerability in Metasploit Express, Community, and Pro editions (versions < 4.14.0) that allows attackers to stop all running tasks by tricking authenticated users into loading a malicious page, due to improper validation of anti-CSRF tokens and the use of GET requests for state-changing operations. The vulnerability was patched by enforcing POST-only requests with CSRF token validation.

CVE-2017-5244 Metasploit Rapid7 Mohamed A. Baset Seekurity Samuel Huckins
seekurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 11 hours ago · details