Menu

#2 CSRF in administration.php

v0.5-beta (bugs)
open-accepted
Pjotr
9
2010-05-31
2010-05-30
Pjotr
No

When deleting an image using URL-parameters (e.g. administration.php?action=foo&subaction=remove&id=bar), it is vulnerable to a CSRF-attack.

Discussion

  • Pjotr

    Pjotr - 2010-05-30
    • assigned_to: nobody --> kameraadpjotr
    • status: open --> open-accepted
     
  • Pjotr

    Pjotr - 2010-05-31
    • milestone: 1143199 --> v0.5-beta (bugs)
     

Log in to post a comment.