jawainc / simplecontact

Contact Us plugin for October CMS
6 stars 13 forks source link

Form CSRF token missing #38

Open vojtasvoboda opened 7 years ago

vojtasvoboda commented 7 years ago

There is no CSRF token at your contact form.

See http://octobercms.com/docs/services/html#form-tokens

Check my Reservations plugin form: https://github.com/vojtasvoboda/oc-reservations-plugin/blob/master/components/reservationform/default.htm#L52

CSRF is one of the most common security problem.

jawainc commented 7 years ago

will look into it