Cross-Site Request Forgery (CSRF) in hdinnovations/unit3d-community-edition
Valid
Reported on
Dec 13th 2021
Description
CSRF to delete user accounts
Proof of Concept
<a href="http://[UNIT3D-URL]/users/{username}/destroy"></a>
Impact
This vulnerability is capable of tricking admin users to delete user accounts
Occurrences
We are processing your report and will contact the
hdinnovations/unit3d-community-edition
team within 24 hours.
2 years ago
user_modals.blade.php#L234L249
has been validated
to join this conversation