plone / plone.protect

HTTP protection utilities for the Plone CMS
https://pypi.org/project/plone.protect/
7 stars 8 forks source link

CSRF Token in URL - concern raised by penetration test #94

Open david-batranu opened 3 years ago

david-batranu commented 3 years ago

The threat, as described in the report:

When transferred in the URL, the CSRF token is leaked in proxy logs and the browser's history. It may further be revealed through referrers. An attacker might be able to perform CSRF attacks, if the token is known.