THREATOPS
THREAT OPSThreat News › [NVD] CVE-2018-11039 (MEDIUM 5.9) — Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a p

[NVD] CVE-2018-11039 (MEDIUM 5.9) — Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a p

lownvdPublished 2018-06-25

CVE-2018-11039 CVSS: 5.9 MEDIUM Published: 2018-06-25T15:29:00.317

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2018-11039