WhisperX tag archive

#mvc

This page collects WhisperX intelligence signals tagged #mvc. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-05-05 21:31:39 · GitHub Issues

1. Critical CSRF Vulnerability in GodObjectProfile Allows Forced Profile Modifications via GET Requests

A critical Cross-Site Request Forgery (CSRF) vulnerability has been identified in the GodObjectProfile component of a .NET 8 MVC application, allowing unauthorized state-mutating operations through standard GET requests. The flaw, reported through the project's issue tracker, exposes authenticated users to forced profi...

The Lab · 2026-05-05 22:31:40 · GitHub Issues

2. CSRF Vulnerability in GodObjectProfile Allows State Mutation via GET Requests on .NET 8 MVC App

A critical Cross-Site Request Forgery vulnerability has been identified in the GodObjectProfile component of a .NET 8 MVC application, allowing state-mutating operations to be triggered through GET requests. The flaw, documented in a GitHub issue, exposes user profile data to unauthorized modification without requiring...

The Lab · 2026-05-07 10:01:46 · GitHub Issues

3. Spring Framework MVC Path Traversal Flaw Targets Static Resource Handling on Non-Compliant Servlet Containers

A path traversal vulnerability has been identified in Spring Framework MVC applications when deployed on Servlet containers that do not enforce strict URI path canonicalization. The flaw specifically affects applications serving static resources through Spring's resource handling mechanism, raising the risk of unauthor...