Cross-Site Request Forgery (CSRF) in livehelperchat
Moderate severity
GitHub Reviewed
Published
Jan 26, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Jan 14, 2022
Reviewed
Jan 24, 2022
Published to the GitHub Advisory Database
Jan 26, 2022
Last updated
Feb 3, 2023
A CSRF issue is found in the audit configuration under settings. It was found that no CSRF token validation is getting done on the server-side. If we remove the CSRF token and keep the CSRF token field empty, the action is getting performed.
References