Description
Important: Bypass of CSRF prevention filter CVE-2012-4431
The CSRF prevention filter could be bypassed if a request was made to a protected resource without a session identifier present in the request.
Affected Apache Tomcat versions (7.0.0 - 7.0.31).
Remediation
Upgrade to the latest version of Apache Tomcat.
References
Related Vulnerabilities
MODX Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-1010123)
WordPress Plugin Ceceppa Multilingua Unspecified Vulnerability (1.5.3)
WordPress Plugin My Calendar Cross-Site Scripting (2.5.16)
SugarCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-35808)
WordPress Plugin Recall Products Multiple Vulnerabilities (0.8)