Hi I can't find the" CSRF rule" in OWASP® ModSecurity Core Rule Set (CRS) version 3.2.0, but I find it in version 2.2.9. I wonder can I use both the rule of version 3.2.0 and version 2.2.9 in the same time? Best Regards
I can't find the" CSRF rule" in OWASP® ModSecurity Core Rule Set (CRS) version 3.3.2, but I find it in version 2.2.9. I wonder is "Cross-site request forgery" still could be protected against by OWASP® ModSecurity Core Rule Set (CRS) 3.3.2 version? If no, can I use both the rule of version 3.3.2 and version 2.2.9 in the same time? Best Regards