Cross-Site Request Forgery (CSRF) in bigprof-software/online-invoicing-system


Reported on

Aug 4th 2021


CSRF bug to ban a member


csrf bug allow to ban any user


1. First goto http://localhost/online-invoice/app/admin/pageViewMembers.php and lets assume there present a member with username test.
Now any user send link http://localhost/online-invoice/app/admin/pageChangeMemberStatus.php?memberID=test&ban=1 to admin and when admin open this link then that user will be banned .
Here no csrf token checking is performed.

We have contacted a member of the bigprof-software/online-invoicing-system team and are waiting to hear back 2 years ago
BigProf Software validated this vulnerability 2 years ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
BigProf Software marked this as fixed with commit 700f4a 2 years ago
BigProf Software has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation