-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
bugSomething isn't workingSomething isn't working
Description
If a student changes the hidden input field within "inspect element" to "Hacker", this allows them to access Hacker's account without even doing XSS. Change the logic of how this form handles submissions so that it will not redirect based on the authentication token from the form.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't working