Description
Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in the URL of a GET request. This could be exploited by an attacker with access to network traffic to perform unauthorized actions.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2023-21979 Vulnerability (CVE-2023-21979)
WordPress Plugin Buddypress Component Stats Local File Inclusion (1.0)
WordPress Plugin WP-Matomo (WP-Piwik) Unspecified Vulnerability (1.0.18)
Zope Web Application Server Other Vulnerability (CVE-2000-1212)
WordPress Plugin Conduit Banner 'banner-index-field-id' Parameter Cross-Site Scripting (0.2)