Cross-Site Request Forgery (CSRF) in namelessmc/nameless

Valid

Reported on

Aug 24th 2021


✍️ Description

csrf bug to stick a topic

🕵️‍♂️ Proof of Concept

Bellow url is vulnerable to csrf attack to stick a topic .

http://localhost/nameless/index.php?route=/forum/stick/&tid=1

💥 Impact

csrf bug to stick a topic

We have contacted a member of the namelessmc/nameless team and are waiting to hear back 2 years ago
Sam validated this vulnerability 2 years ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
Sam marked this as fixed with commit fed921 2 years ago
The fix bounty has been dropped
This vulnerability will not receive a CVE
to join this conversation