Re: For your protection, access to this resource is secured against CSRF.

David Woolley <[email protected]>
Newsgroups gmane.comp.web.lynx.devel
Message-ID <[email protected]>
On 02/01/2023 13:19, jindam.vani--- via Lynx-dev wrote:
> i receive error clicking logout on webmail.disroot.org
> error: "For your protection, access to this resource
> is secured against CSRF. If you see this, you
> probably didn't log out before leaving the web
> application."
> disroot use roundcube for email


I assume this is a fix for CVE-2020-12626 
<https://nvd.nist.gov/vuln/detail/CVE-2020-12626> or maybe a fix for the 
vulnerability that wasn't properly fixed before.

I haven't explored deep into the code, but my guess is that they use 
scripting to calculate a return value that isn't in a cookie.  I'm not 
sure why they can't include that in the submit URL, or a hidden 
parameter, as I think it is only cookies that get returned with injected 
requests.

Do you know the version number (ideally before and after)? The CVE was 
"fixed" in 1.4.4.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.