Cross-Site Search Vulnerability in Google Monorail
CVE-2018-10099
5.3MEDIUM
What is CVE-2018-10099?
Google Monorail, prior to April 4, 2018, contains a Cross-Site Search (XS-Search) vulnerability where CSV downloads are susceptible to Cross-Site Request Forgery (CSRF). This flaw allows an attacker to manipulate download requests, potentially exposing sensitive information regarding bug report content by leveraging the manner in which download times are calculated for requests that contain duplicated columns.