CVE-2018-0785: CSRF
ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerability".
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-0785?
CVE-2018-0785 is a cross site request forgery vulnerability in ASP.NET Core 1.0, 1.1, and 2.0.
What is the severity of CVE-2018-0785?
CVE-2018-0785 has a severity rating of 6.5, which is considered medium.
What software is affected by CVE-2018-0785?
ASP.NET Core 2.0 is affected by CVE-2018-0785.
How can I fix CVE-2018-0785?
To fix CVE-2018-0785, update ASP.NET Core to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2018-0785?
You can find more information about CVE-2018-0785 on the following websites: [SecurityFocus](http://www.securityfocus.com/bid/102379), [SecurityTracker](http://www.securitytracker.com/id/1040151), [Microsoft Security Guidance](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0785).