Loading HuntDB...

Logout CSRF

Low
W
Weblate
Submitted None
Reported by japz

Vulnerability Details

Technical details and impact analysis

Cross-Site Request Forgery (CSRF)
Hi Team, This is a low risk but want you to know that logout on this domain `demo.weblate.org` did not protect the logout form with csrf token, therefor i can logout any user by sending this url `https://demo.webplate.org/accounts/logout/`. Logout should have post method with a valid csrf token. Let me know if you need more info. Regards Japz

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-Site Request Forgery (CSRF)