Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Possible CSRF vulnerability #8

Open
scalzava opened this issue May 15, 2024 · 0 comments
Open

Possible CSRF vulnerability #8

scalzava opened this issue May 15, 2024 · 0 comments

Comments

@scalzava
Copy link

scalzava commented May 15, 2024

To whom it may concern.

Our security team is working on the automated detection of session vulnerabilities in opensource web applications, including CSRF. Our analyzer identified that the submitReading function of /site/exhibitionInferenceSite/exhibitionInferenceApp/views.py has been declared as CSRF exempt. After manual analysis, we believe that this practice might leave your application vulnerable to security-relevant CSRF attempts.

Can you take a look into the relevant code parts and comment on the issue?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant