10-25-2018 12:40 AM - edited 07-05-2021 09:22 AM
We were not able to do add a new user or edit existing one under Lobby Ambassador Guest Management. Nothing happened when we clicked on links/button.
At the same time we saw these messages in logs:
*emWeb: Oct 25 05:41:45.690: %EMWEB-3-FORM_SUBMIT_CSRF_DETECTED: ews_form.c:1229 Form submit action failed. Cross Site Attack detected form_idx=50 url=/screens/aaa/guestuser_create.html formCsrfTbl[50]=1.
*emWeb: Oct 25 05:41:14.435: %EMWEB-3-FORM_SUBMIT_CSRF_DETECTED: ews_form.c:1229 Form submit action failed. Cross Site Attack detected form_idx=52 url=/screens/aaa/guestuser_list.html formCsrfTbl[52]=1.
We googled for "Form submit action failed. Cross Site Attack detected" and we came across at CSCva81409. A workaround, to disable CSRF Check, works.
According to bug notes, it was fixed in: 8.4(100.0), 8.4(1.118), 8.3(114.11), 8.3(111.0), 8.3(104.88), but exists in 8.5.x?
Our controllers 3504 runs on 8.5.131.0
06-05-2019 10:12 AM
I have a 2504 running 8.3.150.0 and I get the message also in the management log. IE: url=/screens/spam/cell_list.html formCsrfTbl[459]=1
06-06-2019 12:49 AM
06-06-2019 05:13 AM
You can check the release notes for 8.5.131.0 and the search bug tool to find if the same issue or similar issue is happening on your version.
I'm guessing, if still happening the bug number changed as the conditions to trigger that issue changed.
Regards
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide