When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.
More information
Veracode static analysis reports [HttpPost] actions of a controller that do not have the [ValidateAntiForgeryToken] annotation on them. You may find more information about Cross-Site Request Forgery protection in .NET applications here: https://docs.microsoft.com/en-us/aspnet/core/security/anti-request-forgery?view=aspnetcore-6.0.
Unfortunately, sometimes the line number information for these actions is not in the debug symbols and so the fallback is to report it on the controller constructor line. Luckily when this happens, the name of the action is able to be captured and this is reported in the "Attack Vector" field in the flaw details that can be found on the Triage Flaws view. An example of this can be seen here, where "write" is the attack vector: