CVE-2019-13594
In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers
In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be accepted by the server.
HIGH · CVSS 8.8
EPSS 0.00141
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0