Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Remediation
References
Related Vulnerabilities
MySQL CVE-2018-3082 Vulnerability (CVE-2018-3082)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-4999)
LimeSurvey Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-7556)
WordPress Plugin Fetch Tweets Unspecified Vulnerability (1.3.3.6)
Oracle Application Server Other Vulnerability (CVE-2004-1774)