plugin_thold icon indicating copy to clipboard operation
plugin_thold copied to clipboard

Security[CSRF]: thold.php use the value of the "Referer" header without validation

Open ddb4github opened this issue 4 years ago • 2 comments

Describe the bug It may be possible to steal or manipulate customer session and cookies, which might be used toimpersonate a legitimate user, allowing the hacker to view or alter user records, and to performtransactions as that use

Expected behavior Validate the value of the "Referer" header, and use a one-time-nonce for each submit

ddb4github avatar Jul 27 '21 06:07 ddb4github

Can you give some more details on what you are meaning with this? Email, page, url ?

netniV avatar Aug 13 '21 13:08 netniV

We pre-escape the REFERER, but I've found that it was double escaped. Fixing now.

TheWitness avatar Sep 07 '21 14:09 TheWitness