Cross Site Request Forgery at refreshing watch list for courses in autolab/autolab
Valid
Reported on
May 13th 2022
Description
Hi there autolab maintainers, there is a CRSF in autolab source code in refreshing watch list due to usage of GET method.
Proof of Concept
- Install a local instance of autolab and create a course
- Access the link
/courses/<course-name>/metrics/refresh_watchlist_instances
and see that any previously added watchlist is archieved.
Impact
CRSF.
Occurrences
We are processing your report and will contact the
autolab
team within 24 hours.
a year ago
We have contacted a member of the
autolab
team and are waiting to hear back
a year ago
The researcher's credibility has increased: +7
We have sent a
fix follow up to the
autolab
team.
We will try again in 7 days.
a year ago
routes.rb#L83
has been validated
to join this conversation