CSRF Token
-
Scanning a site with ZAP leads to alerts about the absence of Anti CSRF Tokens on Contact forms. I have captcha v3 running and have enabled NONCE as mentioned here but nothing has changed https://contactform7.com/2017/08/18/contact-form-7-49/#:~:text=Contact%20Form%207%20verifies%20a,determine%20whether%20to%20verify%20nonces
Is there any way to add anti-CSRF tokens to contact form 7 or any other approach I can use to eliminate these ZAP alerts?
Viewing 3 replies - 1 through 3 (of 3 total)
Viewing 3 replies - 1 through 3 (of 3 total)
- The topic ‘CSRF Token’ is closed to new replies.