CVE-2018-20595

A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the request is not compared with the state parameter in the session after user authentication is successful.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:hsweb:hsweb:3.0.4:*:*:*:*:*:*:*

Information

Published : 2018-12-30 10:29

Updated : 2019-01-14 06:52


NVD link : CVE-2018-20595

Mitre link : CVE-2018-20595


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

Advertisement

dedicated server usa

Products Affected

hsweb

  • hsweb