Skip to content
WJunction - Webmaster Forum

ChatBox Vulnerability

Status
Not open for further replies.
It has come to my attention that the WJunction ChatBox is vulnerable to a CSRF attack.

Moderators have been tricked into loading URL's that look like this:

Ln4OC.png


When such links are inserted into "IMG" tags within a post; a moderator will unknowingly ban the user from the ChatBox. In the past few minutes alone, myself and other members of staff have fallen victim to this attack (the links having made us ban ourselves).

This makes it impossible to moderate the ChatBox effectively. It is therefore necessary to disable the ChatBox until further notice.

Thank you.
 

1 comment

Status
Not open for further replies.

About the author

L
Active Member · Joined
2,124
Messages
732
Reactions
113
Points

Advertise on WJunction

Reach 1000's of webmasters, hosts & affiliates. Banner & sponsored-thread slots available.

Contact us
Back
Top Bottom