-
Notifications
You must be signed in to change notification settings - Fork 1.8k
Open
Description
A Cross-Site Request Forgery (CSRF) vulnerability exists in KodExplorer that allows an attacker to create a new administrator user without authentication by tricking a logged-in admin into sending a malicious request.
"X-CSRF-TOKEN" in header and also in cookie are useless and not sanitized in backend.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels