[EP-tech] CSRF Vulnerability in EPrints
Adam Field via Eprints-tech <[email protected]>
| Newsgroups | gmane.comp.web.eprints.devel |
|---|---|
| Message-ID | <EMEW3|93bc42f2cc8c6f3054e0533d84e19014v2R9uM14eprints-tech-bounces|ecs.soton.ac.uk|[email protected]> |
Hi We’ve had a report from an independent security researcher (Jisc’s policy encourages reporting of issues) that EPrints suffers from a CSRF vulnerability. The fix for this would be to add tokens to forms so that EPrints can validate that a submitted form was one that it generated. This is obviously a fairly complex problem to solve, with changes to multiple parts of EPrints, probably requiring a new field type, as well as the storing of tokens somewhere (perhaps a new dataset). Has anyone taken a look at this? Thanks -- Adam *** Options: http://mailman.ecs.soton.ac.uk/mailman/listinfo/eprints-tech *** Archive: http://www.eprints.org/tech.php/ *** EPrints community wiki: http://wiki.eprints.org/ *** EPrints developers Forum: http://forum.eprints.org/