Cross-Site Request Forgery (CSRF) in namelessmc/nameless
Valid
Reported on
Aug 24th 2021
✍️ Description
csrf bug to follow a topic
🕵️♂️ Proof of Concept
i see everywhere is csrf token checking . But in this case csrf token checking is missing .
Bellow url is vulnerable to csrf attack to follow a topic .
http://localhost/nameless/index.php?route=/forum/topic/1/&action=follow
💥 Impact
csrf bug to follow a topic
Occurrences
We have contacted a member of the
namelessmc/nameless
team and are waiting to hear back
2 years ago
to join this conversation