VYPR

Csrf Magic

by Ezyang

Source repositories

CVEs (1)

  • CVE-2013-7464HigAug 8, 2018
    risk 0.57cvss 8.8epss 0.01

    In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, because an automatically generated secret is not used.