Docuware haz a whole lotta not giving a shit about CSRF.
"Hey, you are vulnerable to CSRF, see."
"HERE'S THE WRONG INSTRUCTIONS TO ADD SAMESITE TO THE COOKIE!"
"Those are wrong, and Samesite doesn't really fix CSRF, what about this auth header you are ignor"
"WE ARE FOLLOWING OWASP STANDARDS"
"Well, no, OWASP does mention samesite, and it's weaknesses, but this is asp.net, CSRF protection is built in if it is just enab"
"HERE'S THE WRONG INSTRUCTIONS TO ADD SAMESITE TO THE COOKIE!"
"We went over this, that doesn't wo"
"BUY OUR CLOUD VERSION!"
Fuck off.
#appsec #csrf