It's not appropriate to discuss software vulnerabilities on a publicly archived thread. If a bug does exist, then it should be raised quietly so that people get told about it at the same time as an upgrade or patch to fix it.

                We’ve had a report from an independent security researcher (Jisc’s policy encourages reporting of issues) that EPrints suffers from a CSRF vulnerability.  The fix for this would be to add tokens to forms so that EPrints can validate that a submitted form was one that it generated.

                This is obviously a fairly complex problem to solve, with changes to multiple parts of EPrints, probably requiring a new field type, as well as the storing of tokens somewhere (perhaps a new dataset).  Has anyone taken a look at this?



