dotnet-security-guard/roslyn-security-guard

Missing ValidateAntiForgeryToken

h3xstream opened this issue · 0 comments

Very simple pattern..

Vulnerable :

        [HttpPost]
        public ActionResult ControllerMethod(string input) {

            return null;
        }

Solution:

        [HttpPost]
        [ValidateAntiForgeryToken]
        public ActionResult ControllerMethod(string input) {

            return null;
        }