@[email protected]
link
fedilink
English
171Y

Wow, his response. Someone needs to fork this project because this guy isn’t living in the real world.

Skull giver
link
fedilink
5
edit-2
1Y

Nah, I’m with this dev on this one.

To make this work, you need the session cookie of an admin, or be able to set the cookie on an admin’s computer. This “attack” works against almost any website, including Lemmy. In fact, the requirement for the URL token makes OpenCart more secure than 90% of websites out there.

He sure didn’t respond professionally, but if this is the kind of “security vulnerabilities” he has to deal with every day, I totally understand.

There are bigger OpenCart issues that do warrant a better response, of course.

Create a post

This is the official technology community of Lemmy.ml for all news related to creation and use of technology, and to facilitate civil, meaningful discussion around it.


Ask in DM before posting product reviews or ads. All such posts otherwise are subject to removal.


Rules:

1: All Lemmy rules apply

2: Do not post low effort posts

3: NEVER post naziped*gore stuff

4: Always post article URLs or their archived version URLs as sources, NOT screenshots. Help the blind users.

5: personal rants of Big Tech CEOs like Elon Musk are unwelcome (does not include posts about their companies affecting wide range of people)

6: no advertisement posts unless verified as legitimate and non-exploitative/non-consumerist

7: crypto related posts, unless essential, are disallowed

  • 1 user online
  • 51 users / day
  • 90 users / week
  • 284 users / month
  • 2.04K users / 6 months
  • 1 subscriber
  • 3.25K Posts
  • 45K Comments
  • Modlog