Quote:
Originally Posted by RS_Jelle
Have a look at the last quote/response in https://vborg.vbsupport.ru/showthrea...69#post2116469
Without the token, people could post download links inside of IMG tags (CSRF issue), but that's only a real problem if you have big downloads combined with download size limitations for usergroups.
|
Hey RS_Jelle,
I am also getting a lot of users emailing me about the 'invalid security token' issue.
What if I'm not allowing any members or guests the ability to upload files? And only allowing members, not guests, to download files? Am I safe from the CSRF issue if I take out the guest hash code?