OSV 1.4.0 · github-reviewed · 修改于 2022-07-14 02:55
发布时间
2021-09-03 01:16
GitHub 审查时间
2021-08-31 01:23
NVD 发布时间
2021-08-14 01:15
源文件
advisories/github-reviewed/2021/09/GHSA-vpw5-grxx-v396/GHSA-vpw5-grxx-v396.json
When using the CsrfTokenViewHelper the extension discloses the user's session identifier to HTML output without processing of additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack - like for instance Cross Site Scripting in the frontend output.