Cross-Site Request Forgery (CSRF) in namelessmc/nameless


Reported on

Aug 24th 2021

✍️ Description

csrf bug to lock a topic

🕵️‍♂️ Proof of Concept

i see everywhere is csrf token checking . But in this case csrf token checking is missing .
Bellow url is vulnerable to csrf attack to lock a topic .


💥 Impact

csrf bug to lock a profile


We have contacted a member of the namelessmc/nameless team and are waiting to hear back 2 years ago
Sam validated this vulnerability 2 years ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
Sam marked this as fixed with commit d36a28 2 years ago
Sam has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation