Closed (fixed)
Project:
Memcache Storage
Version:
7.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
5 Aug 2013 at 15:34 UTC
Updated:
20 Aug 2013 at 08:51 UTC
The ajax bin clearing doesn't use tokens nor a confirmation to protect against csrf.
Some CSRF protection is necessary to prevent an attacker from clearing all bins.
Comments
Comment #1
spleshkaThanks for you report, fixed (bd8d3bf).