Menu

#47 jforum csrf vulnerability fix

Fixed
nobody
None
Medium
Defect
2015-01-23
2013-10-27
Anonymous
No

Originally created by: kadir.ba... (code.google.com)@gmail.com
Originally owned by: andow... (code.google.com)@gmail.com

hello , we have seen csrf vulnerability on jforum.

There is as fix here:
https://github.com/boyarsky/jforumCsrf

But i could not found how to compile and run fixer
Here is ZerodayLab specification:
http://www.zerodaylab.com/zdl-advisories/2012-5337.html

Related

Wiki: NewFeatures240

Discussion

  • Anonymous

    Anonymous - 2013-10-28

    Originally posted by: andow... (code.google.com)@gmail.com

    Please check or fix it

    Owner: ulf.dittmer

     
  • Anonymous

    Anonymous - 2015-01-23

    Originally posted by: andow... (code.google.com)@gmail.com

    I've done some fix for CSRF in [r382]. Try it.

    Owner: andow...@gmail.com
    Status: Fixed

     

Log in to post a comment.

MongoDB Logo MongoDB