Modify

Opened 5 years ago

Last modified 4 years ago

#10227 new defect

Bookmark plugin should protect add and delete operations

Reported by: Jun Omae Owned by: Ryan J Ollos
Priority: normal Component: BookmarkPlugin
Severity: major Keywords:
Cc: Jun Omae, Ryan J Ollos, Steffen Hoffmann Trac Release: 0.12

Description

The bookmark icon is simple link, not a form. The delete link in bookmark page is also. Therefore, a attacker can force to add and delete the users' bookmarks.

Attachments (0)

Change History (4)

comment:1 Changed 4 years ago by Ryan J Ollos

Cc: Ryan J Ollos Steffen Hoffmann added

In as much as I understand this, the issues appears to be similar to #7744 for the VotePlugin.

comment:2 in reply to:  1 Changed 4 years ago by Steffen Hoffmann

Replying to rjollos:

In as much as I understand this, the issues appears to be similar to #7744 for the VotePlugin.

Yes, you're right.

comment:3 Changed 4 years ago by Ryan J Ollos

Owner: changed from yosiyuki to Ryan J Ollos
Status: newassigned

comment:4 Changed 4 years ago by Ryan J Ollos

Status: assignednew

Modify Ticket

Change Properties
Set your email in Preferences
Action
as new The owner will remain Ryan J Ollos.

Add Comment


E-mail address and name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.