Skip to content

Conversation

@jamesros161
Copy link
Collaborator

@jamesros161 jamesros161 commented Aug 29, 2023

ISSUE: Resolves #540

Add Nonce Validation to formActionRoute

This vulnerability was reported based on the submitDefaultEditor method not using nonce validation. However, this method is actually called by the formActionRoute , therefore the nonce validation is being added there.

@jamesros161 jamesros161 merged commit 47ad8a2 into master Aug 29, 2023
@jamesros161 jamesros161 deleted the cvefix branch August 29, 2023 17:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CSRF vulnerability in the submitDefaultEditor function

4 participants