Jul 22nd 2021

csrf bug to change email


  1. First login into your account and open the link http://localhost/emoncms/user/changeemail.json?&email=admin%40localhost.combm and your email will be changed.


Any attacker can send those link to vicitm and when vicitm open the link then email will be changed

A emoncms/dashboard maintainer
a year ago


Thanks @ranjit-git , I have a fix for this working its way into the core at the moment setting the samesite cookie property to strict, will link and update this shortly

A emoncms/dashboard maintainer
a year ago


Here's the fix in the core repo

I will link last commit in the dashboard repo to close this issue.

Thanks again!

