Cross-Site Request Forgery (CSRF) in bigprof-software/online-rental-property-manager

Valid

Reported on

Jul 4th 2021


💥 BUG

csrf to turn off maintanance-mode

💥 VERSION TESTED

latest version as of 4/7/21

💥 STEP TO REPRODUCE

1. just visit http://localhost/online-rental/app/admin/ajax-maintenance-mode.php?status=off and it will turn-off maintenance-mode if already enabled.
Here no csrf token is checking

We have contacted a member of the bigprof-software/online-rental-property-manager team and are waiting to hear back a year ago
BigProf Software validated this vulnerability a year ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
BigProf Software marked this as fixed with commit 41ed21 a year ago
BigProf Software has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation