Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Remediation
References
Related Vulnerabilities
MediaWiki Improper Privilege Management Vulnerability (CVE-2018-0503)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-0346)
WordPress Plugin WP Mapa Politico Espana Cross-Site Scripting (3.6.2)
Coppermine Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2008-3481)