Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, because an automatically generated secret is not used.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
csrf-magic 安全漏洞
Vulnerability Description
csrf-magic是一个使用在PHP应用程序中,用于防护CSRF(跨站请求伪造)攻击的包。 csrf-magic 1.0.4之前版本中存在安全漏洞,该漏洞源于在没有配置$GLOBALS['csrf']['secret']时,很容易猜测出所使用的反跨站请求伪造令牌。攻击者可利用该漏洞绕过跨站请求伪造防护。
CVSS Information
N/A
Vulnerability Type
N/A