Cross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat


Reported on

Aug 24th 2021

✍️ Description

csrf bug to make clone of a role

🕵️‍♂️ Proof of Concept

i see everywhere csrf token is checking but during cloning of role, it does not check csrf token .
Belllow url is vulnerable to csrf attack to make a clone of role

💥 Impact

csrf bug to clone a role


We have contacted a member of the livehelperchat team and are waiting to hear back a year ago
Remigijus Kiminas validated this vulnerability a year ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
Remigijus Kiminas confirmed that a fix has been merged on f7584a a year ago
The fix bounty has been dropped
