Skip to content

CSRF vulnerability in 4.52 #539

@code5ecure

Description

@code5ecure

A Cross-Site Request Forgery (CSRF) vulnerability exists in KodExplorer that allows an attacker to create a new administrator user without authentication by tricking a logged-in admin into sending a malicious request.
"X-CSRF-TOKEN" in header and also in cookie are useless and not sanitized in backend.

https://github.com/code5ecure/KodExplorer

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions