View Issue Details

IDProjectCategoryView StatusLast Update
0007059OXID eShop (all versions)1.05. Userspublic2022-08-22 12:42
ReporterJCT Assigned To 
PriorityurgentSeveritycrashReproducibilityalways
Status resolvedResolutionfixed 
Product Version6.1.5 
Fixed in Version6.4.2 
Summary0007059: CreateUser does not check CSRF/session token
DescriptionAt the moment it is possible to execute the register form in the frontend without an valid csrf/session token. The token will be neither checked or validated.
Steps To Reproduce1. Visit the frontend and open register as new user
2. Remove the stoken value from the register form
3. Submit the form
TagsAccount, Security, Session, Validation
ThemeAll
BrowserAll
PHP VersionAll
Database VersionAll

Activities

QA

2019-12-13 15:18

administrator   ~0013067

possible security issue > view status to private

QA

2019-12-13 15:27

administrator   ~0013068

@JCT: please have in mind, that security issues should be send to [email protected]. I have informed them.

-MF

QA

2022-08-22 12:42

administrator   ~0014123

Set the view status to public.
-MK