Vulnerabilities > CVE-2017-9785 - Deserialization of Untrusted Data vulnerability in Nancyfx Nancy 2.0.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
nancyfx
CWE-502

Summary

Csrf.cs in NancyFX Nancy before 1.4.4 and 2.x before 2.0-dangermouse has Remote Code Execution via Deserialization of JSON data in a CSRF Cookie.

Vulnerable Configurations

Part Description Count
Application
Nancyfx
4

Common Weakness Enumeration (CWE)