cve/2024/CVE-2024-22859.md
2024-06-18 02:51:15 +02:00

802 B

CVE-2024-22859

Description

** DISPUTED ** Cross-Site Request Forgery (CSRF) vulnerability in livewire before v3.0.4, allows remote attackers to execute arbitrary code getCsrfToken function. NOTE: the vendor disputes this because the 5d88731 commit fixes a usability problem (HTTP 419 status codes for legitimate client activity), not a security problem.

POC

Reference

Github

No PoCs found on GitHub currently.