Description
Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in the URL of a GET request. This could be exploited by an attacker with access to network traffic to perform unauthorized actions.
Remediation
References
Related Vulnerabilities
WordPress Plugin Microblog Poster SQL Injection (1.6.0)
WordPress Plugin FormBuilder Cross-Site Scripting (0.90)
Python Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2019-20907)
MySQL CVE-2024-21047 Vulnerability (CVE-2024-21047)
Dolibarr Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-17898)