Csrf in watch-unwatch projects

Disclosed: 2017-08-17 16:18:23 By ashish_r_padelkar To weblate
Low
Vulnerability Details
Hello, When you visit any projects from `https://hosted.weblate.org/` , there is a button provided on top-right called `Watch` / `Unwatch` for each projects. when you click on that button, a POST request is sent which contains csrf token. But this request also works without that token. Just hit the urls in your browser and you will be able to `Watch` or `Unwatch` the projects `https://hosted.weblate.org/accounts/watch/androbd/` https://hosted.weblate.org/accounts/unwatch/androbd/ where androbd is a project name! Regrads Ashish
Actions
View on HackerOne
Report Stats
  • Report ID: 229405
  • State: Closed
  • Substate: resolved
  • Upvotes: 5
Share this report