Total vulnerabilities in the database
A number of form actions in the Forum module are directly accessible. A malicious user (e.g. spammer) can use GET requests to create Members and post to forums, bypassing CSRF and anti-spam measures.
Additionally, a forum moderator could be tricked into clicking a specially crafted URL, resulting in a topic being moved.
Thanks to Michael Strong for discovering.
Software | From | Fixed in |
---|---|---|
![]() |
- | 0.6.2 |
![]() |
0.7.0 | 0.7.4 |