Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Remediation
References
Related Vulnerabilities
PHP Out-of-bounds Read Vulnerability (CVE-2019-11035)
Oracle Database Server Other Vulnerability (CVE-2001-0515)
WordPress Plugin WP Support Plus Responsive Ticket System Security Bypass (7.1.4)
WordPress Plugin Convert Plus Unspecified Vulnerability (3.5.6)
TYPO3 Insertion of Sensitive Information into Log File Vulnerability (CVE-2021-32767)