Privilege escalation in ASP.NET Core MVC - CVE-2018-0784
Published: January 9, 2018
ASP.NET Core MVC
Detailed vulnerability description
The vulnerability allows a remote attacker to gain elevated privileges on the target system.
The weakness exists due to an error when a ASP.NET Core web application, created using vulnerable project templates, improperly sanitize web requests. A remote attacker can trick the victim into clicking a specially crafted link, perform content injection attacks and run script in the security context of the logged-on user.