CVE-2018-0785
published 2018-01-10CVE-2018-0785: ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request…
PriorityP427medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
3.03%
86.1th percentile
ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerability".
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | asp.net_core | — | — |
| microsoft_corporation | asp.net_core | — | — |
| msrc | asp.net_core_2.0 | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
ASP.NET Core Cross Site Request Forgery Vulnerabilty
vendor_msrc·2018-01-09·CVSS 6.5
CVE-2018-0785 [MEDIUM] ASP.NET Core Cross Site Request Forgery Vulnerabilty
ASP.NET Core Cross Site Request Forgery Vulnerabilty
Description: A Cross Site Request Forgery (CSRF) vulnerability exists when a ASP.NET Core web application is created using vulnerable project templates.
An attacker who successfully exploited this vulnerability could change the recovery codes associated with the victim's user account without his/her consent.
As a result, a victim of this attack may be permanently locked out of his/her account after loosing access to his/her 2FA device, as the initial recovery codes would be no longer valid.
The update corrects the ASP.NET Core project templates.
FAQ: What does the update do?
The update corrects the project templates for ####.
The template updates only affect new applications. For this reason, Microsoft strongly recommends that develope
GHSA
GHSA-8r33-7h89-2vmx: ASP
ghsa_unreviewed·2022-05-14
CVE-2018-0785 [MEDIUM] CWE-352 GHSA-8r33-7h89-2vmx: ASP
ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerability".
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/102379http://www.securitytracker.com/id/1040151https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0785http://www.securityfocus.com/bid/102379http://www.securitytracker.com/id/1040151https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0785
2018-01-10
Published