Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data, and text/plain.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.seleniumhq.selenium:selenium-grid(Maven) | 0 | 4.0.0-alpha-7 | N/A |
| org.seleniumhq.selenium:selenium-server(Maven) | 0 | N/A | N/A |
CVSS Metrics