cve/2023/CVE-2023-45857.md
2024-05-25 21:48:12 +02:00

1.1 KiB

CVE-2023-45857

Description

An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.

POC

Reference

No PoCs from references.

Github