Cross-Site Request Forgery (CSRF) in namelessmc/nameless
Valid
Reported on
Aug 24th 2021
✍️ Description
csrf bug to stick a topic
🕵️♂️ Proof of Concept
Bellow url is vulnerable to csrf attack to stick a topic .
http://localhost/nameless/index.php?route=/forum/stick/&tid=1
💥 Impact
csrf bug to stick a topic
Occurrences
We have contacted a member of the
namelessmc/nameless
team and are waiting to hear back
2 years ago
to join this conversation