Download & Extend

Add token to the end of voting URLs

Project:UpDown
Component:Code
Category:bug report
Priority:critical
Assigned:gregnostic
Status:closed (fixed)

Issue Summary

This module doesn't check to see whether the user intended to load the URL when a vote is cast, leaving the module open to a CSRF attack, the scope of which is limited to unwittingly casting votes. Adding a token to the end of the URL should suffice.

Comments

#1

subscribe

#2

Status:active» closed (fixed)

handled by dmitrig