OFFLINE-GmbH / oc-gdpr-plugin

October CMS plugin to make websites GDPR and ePrivacy compliant

Home Page:https://octobercms.com/plugin/offline-gdpr

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Security Issue - Cross-site request forgery (CRSF Attacks)

opened this issue · comments

There is no CRSF Protection on the POST Form (cookie-manager), missing the CRSF Token!

Also could add a Honey Pot Protection to the Form to Stop Spam Bots.