igniterealtime/openfire-xmldebugger-plugin

CSRF protection support

GregDThomas opened this issue · 1 comments

The (only) JSP page on this plugin is vulnerable to CSRF attacks. Although the attack is limited to enabling/disabling various loggings, this should be guarded against.

Fixed by way of #8