XSS, CSRF replace by lispro06 · Pull Request #246 · 4clojure/4clojure · GitHub
Skip to content
This repository was archived by the owner on Dec 30, 2025. It is now read-only.

XSS, CSRF replace#246

Open
lispro06 wants to merge 1 commit into
4clojure:developfrom
lispro06:patch-1
Open

XSS, CSRF replace#246
lispro06 wants to merge 1 commit into
4clojure:developfrom
lispro06:patch-1

Conversation

@lispro06

@lispro06 lispro06 commented Sep 9, 2013

Copy link
Copy Markdown

security vulnerability remove

security vulnerability remove
@lispro06

lispro06 commented Sep 9, 2013

Copy link
Copy Markdown
Author

@lispro06

lispro06 commented Sep 9, 2013

Copy link
Copy Markdown
Author

<form name="csrf" action="http://~/problem/reject" method="post" target="hidden">
<input type="hidden" name="id" value="91" />
</form>
<script>document.csrf.submit();</script>

above CSRF is remove value(91) problem using approved user's authority.

@amcnamara

Copy link
Copy Markdown
Member

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants