Jump to content

Dev mode exception from CSRF left in URL when enabling MFA


Recommended Posts

To reproduce, enable security questions in the account security menu.

Quote

ErrorException: An 200 response is being sent however the CSRF key is present in the requested URL. CSRF keys should be sent via POST or the request should be redirected to a URL not containing a CSRF key once finished. (256)

The URL is

/settings/account-security/&act=enable&type=questions&_new=1&csrfKey=(omitted)

 

Link to comment
Share on other sites

Thank you for bringing this issue to our attention! I can confirm this should be further reviewed and I have logged an internal bug report for our development team to investigate and address as necessary, in a future maintenance release.

 

Link to comment
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...