Cross-Site Request Forgery (CSRF) in bigprof-software/online-rental-property-manager

Valid
Reported on Jul 4th 2021

💥 BUG

csrf to turn off maintanance-mode

💥 VERSION TESTED

latest version as of 4/7/21

💥 STEP TO REPRODUCE

1. just visit http://localhost/online-rental/app/admin/ajax-maintenance-mode.php?status=off and it will turn-off maintenance-mode if already enabled.
Here no csrf token is checking

We have contacted a member of the bigprof-software/online-rental-property-manager team and are waiting to hear back 22 days ago
BigProf Software validated this vulnerability 16 days ago
ranjit-git has been awarded the disclosure bounty
$25
The fix bounty is now up for grabs
$6.25
BigProf Software confirmed that a fix has been merged on 41ed21 16 days ago
BigProf Software has been awarded the fix bounty
$6.25