Csrf.cs in NancyFX Nancy before 1.4.4 and 2.x before 2.0-dangermouse has Remote Code Execution via Deserialization of JSON data in a CSRF Cookie.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/BitcoinChatGPT/DeserializeSignature-Vulnerability-Algorithm
- https://github.com/BitcoinChatGPT/Joux-Lercier-Vulnerability-Algorithm
- https://github.com/dotnet-felickz/vulnerable-dependencies