Cross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat
Valid
Reported on
Aug 24th 2021
✍️ Description
csrf bug to make clone of a role
🕵️♂️ Proof of Concept
i see everywhere csrf token is checking but during cloning of role, it does not check csrf token .
Belllow url is vulnerable to csrf attack to make a clone of role
https://demo.livehelperchat.com/site_admin/permission/clonerole/1
💥 Impact
csrf bug to clone a role
Occurrences
We have contacted a member of the
livehelperchat
team and are waiting to hear back
2 years ago
The fix bounty has been dropped
This vulnerability will not receive a CVE
to join this conversation