Cross-Site Request Forgery (CSRF) in bigprof-software/online-invoicing-system


Reported on

Aug 4th 2021


CSRF bug to ban a member


csrf bug allow to ban any user


1. First goto http://localhost/online-invoice/app/admin/pageViewMembers.php and lets assume there present a member with username test.
Now any user send link http://localhost/online-invoice/app/admin/pageChangeMemberStatus.php?memberID=test&ban=1 to admin and when admin open this link then that user will be banned .
Here no csrf token checking is performed.

We have contacted a member of the bigprof-software/online-invoicing-system team and are waiting to hear back 4 months ago
BigProf Software validated this vulnerability 3 months ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
BigProf Software confirmed that a fix has been merged on 700f4a 3 months ago
BigProf Software has been awarded the fix bounty