Skip to main content

Microsoft ASP.NET Access Control Vulnerability

Last Update Date: 11 Feb 2016 11:31 Release Date: 11 Feb 2016 3291 Views

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

A vulnerability has been identified in Microsoft ASP.NET. A remote user can conduct cross-site request forgery attacks to remove two-factor authentication. Password authentication is not affected.


Impact

  • Cross-Site Scripting

System / Technologies affected

  • MVC5
  • MVC6

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has described how to modify the templates to fix the vulnerability.

Vulnerability Identifier

  • No CVE information is available

Source


Related Link