Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Lightbend Play Framework 跨站请求伪造漏洞
Vulnerability Description
Lightbend Play Framework是美国Lightbend公司的一款使用Scala语言编写的Web应用程序框架。 Lightbend Play Framework 2.6.0版本至2.8.1版本中存在安全漏洞。攻击者可借助格式错误的‘Content-Type’参数利用该漏洞绕过针对内容类型的黑名单。
CVSS Information
N/A
Vulnerability Type
N/A