[ 
https://issues.apache.org/jira/browse/OPENMEETINGS-947?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13934443#comment-13934443
 ] 

Maxim Solodovnik commented on OPENMEETINGS-947:
-----------------------------------------------

I'm afraid this report does not make much sense
There are no such files in our sources: Check.jsp
Please provide more details

> Cross-Site Request Forgery
> --------------------------
>
>                 Key: OPENMEETINGS-947
>                 URL: https://issues.apache.org/jira/browse/OPENMEETINGS-947
>             Project: Openmeetings
>          Issue Type: Test
>         Environment: Windows 8
>            Reporter: Kriti Gupta
>            Priority: Critical
>              Labels: security
>
> A cross-site request forgery (CSRF) vulnerability occurs when:
> 1. A Web application uses session cookies.
> 2. The application acts on an HTTP request without verifying that the request 
> was made with the user's consent.
> In this case the application generates HTTP request via a form post at 
> Check.jsp line 16.



--
This message was sent by Atlassian JIRA
(v6.2#6252)

Reply via email to