WhisperX tag archive

#CSRF vulnerability

This page collects WhisperX intelligence signals tagged #CSRF vulnerability. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-04-29 20:54:11 · GitHub Issues

1. CSRF Protection Absent on Key API Endpoints: Default Config Exposes Admin Actions to Malicious Requests

A security vulnerability has been identified in multiple state-mutating REST API endpoints under `/api/v1/`, where Cross-Site Request Forgery (CSRF) token validation is not enforced when the default configuration `WTF_CSRF_ENABLED` is set to `False`. The flaw affects administrative functions including dashboard saves, ...

The Lab · 2026-05-09 20:31:50 · GitHub Issues

2. SQL Injection Vulnerability Detected in VoluntarioControle.php: CSRF Controls Under Scrutiny

A security analysis of the PHP file web/controle/VoluntarioControle.php has uncovered potential vulnerabilities that could expose volunteer management systems to exploitation. The most critical finding points to SQL injection risks, with no evidence of parameterized queries in the codebase—a gap that could allow attack...