Comment/channel unsubscribe GET CSRF
Low
E
ExpressionEngine
Submitted None
Team Summary
Official summary from ExpressionEngine
A vulnerability was identified and fixed that could have allowed attackers to unsubscribe users from comment notifications by exploiting the lack of CSRF protection.
Actions:
Reported by
d0bby
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-Site Request Forgery (CSRF)