PT-2021-8422 · Github.Com/Dinever/Golf+3 · Github.Com/Dinever/Golf+1

Elithrar

·

Published

2021-04-14

·

Updated

2025-04-11

·

CVE-2016-15005

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue is related to the generation of CSRF tokens using a non-cryptographically secure random number generator, specifically math/rand. This allows an attacker to predict the values of these tokens with relatively few requests, effectively bypassing CSRF protections.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-15005
GHSA-Q9QR-JWPW-3QVV
GO-2020-0045

Affected Products

Github.Com/Dinever/Golf
Golf