A security scan using Acunetix software is claiming that the login form does not have CSRF protection in version 7.6.6.
I see the cookie token in developer tools. Is this a false positive? Can someone confirm that CSRF protection is present, and show details, if you have the time.
CSRF protection
A security scan using Acunetix software is claiming that the login form does not have CSRF protection in version 7.6.6.
I see the cookie token in developer tools. Is this a false positive? Can someone confirm that CSRF protection is present, and show details, if you have the time.
Thank you.
Tested the CSRF protection with Acunetix tools. They are indeed false positives.
is working on a reply...