Cross-Site Request Forgery (CSRF) in namelessmc/nameless
Valid
Reported on
Aug 24th 2021
✍️ Description
csrf bug to lock a topic
🕵️♂️ Proof of Concept
i see everywhere is csrf token checking . But in this case csrf token checking is missing .
Bellow url is vulnerable to csrf attack to lock a topic .
http://localhost/nameless/index.php?route=/forum/lock/&tid=1
💥 Impact
csrf bug to lock a profile
Occurrences
We have contacted a member of the
namelessmc/nameless
team and are waiting to hear back
2 years ago
to join this conversation