Search

Contact Us

Log in

Vulnerabilities / Missing cross-site request forgery protection

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Severity
low
CWE NameMissing cross-site request forgery protection
CWE IDCWE-352
CWE Score6.5
Compliance
OWASP TOP10 -> A7
PCI-DSS -> 6.5.9, 6.5.10
ISO 27001 -> A.8.2, A.8.3
HIPAA -> 164.306(a)
CVSS3.0
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeUnchanged
Confidentiality ImpactNone
Integrity ImpactHigh
Availability ImpactNone
Missing cross-site request forgery protection