Filtered by vendor Madeofcode
Subscriptions
Filtered by product Omniauth-facebook
Subscriptions
Total
1 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2013-4562 | 1 Madeofcode | 1 Omniauth-facebook | 2024-11-21 | N/A |
The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter. |
Page 1 of 1.