plugin_thold
plugin_thold copied to clipboard
Security[CSRF]: thold.php use the value of the "Referer" header without validation
Describe the bug It may be possible to steal or manipulate customer session and cookies, which might be used toimpersonate a legitimate user, allowing the hacker to view or alter user records, and to performtransactions as that use
Expected behavior Validate the value of the "Referer" header, and use a one-time-nonce for each submit
Can you give some more details on what you are meaning with this? Email, page, url ?
We pre-escape the REFERER, but I've found that it was double escaped. Fixing now.