UserPreferencesResource accepts form encoded data, is vulnerable to XSRF attacks

XMLWordPrintable

    • 4.9

      UserPreferencesResource exposes all data stored in a UserPreferences object, and allows updating it via a POST. This vulnerability needs to be closed before the next deployment.

              Assignee:
              Hai Nguyen (Inactive)
              Reporter:
              Richard Atkins
              Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: