Ratings security is lacking. Its not using sesskey() and confirm_sesskey()/require_sesskey() and is thus vulnerable to CSRF.
Is it possible to rate yourself by hand crafting a URL?
- has a non-specific relationship to
-
MDL-21657 Implement Ratings 2.0
-
- Closed
-