- Affected version
- 2.1.7
Description
Post the URL to an unread thread as
Expected Result
The attacked thread is not marked read as the user never really read it
Actual Result
XF accepts the request issued by the browser and marks the thread read
Suggested Mitigation
Prevent GET requests initiated by images from marking content read, maybe also do not change online location in this case
Post the URL to an unread thread as
[img]
and view the contetn containing this BBCodeExpected Result
The attacked thread is not marked read as the user never really read it
Actual Result
XF accepts the request issued by the browser and marks the thread read
Suggested Mitigation
Prevent GET requests initiated by images from marking content read, maybe also do not change online location in this case