iScsc / iscsc.fr

The iScsc website, build with passion by wannabe devs 🔥
GNU General Public License v3.0
4 stars 12 forks source link

Vulnerability against CSRF #24

Open ctmbl opened 2 years ago

ctmbl commented 2 years ago

Context: I was just wondering, is the website vulnerable to CSRF?

Problem: Does this attack scenario would work:

Nothing is done in the source code to protect the blog against these attacks but maybe the framework used do it already?

Other: Another minor question, how long is the website cookie valid?