chshcms / mccms

漫城CMS(mccms)是一款采用CI框架开发的漫画、小说内容管理系统
Apache License 2.0
51 stars 13 forks source link

Under v2.6.3, your project has a CSRF vulnerability #3

Open NHotthat opened 1 year ago

NHotthat commented 1 year ago

There are CSRF vulnerabilities in the website. The front desk can modify user information, and the background can add administrator accounts, modify the balance held by users, modify the website configuration and other dangerous operations. It is recommended to add CSRF TOKEN or verify referer to defend image image image image

chshcms commented 1 year ago

谢谢~已修复~