4.3
CVSSv2

CVE-2020-12480

Published: 17/08/2020 Updated: 24/08/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

In Play Framework 2.6.0 up to and including 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lightbend play framework