Notice: We are now selling NEW Gelbooru Merch~! Domestic shipping is free on all orders! Do you have an artist tag on Gelbooru? Let us know so we can properly credit you!

Ticket Information - ID: #959

ID:Category:SeverityReproducibilityDate SubmittedUpdated By:
0000959Bug ReportingHighsometimes01/08/19 04:44PM
Assigned to:lozertuser
View StatusPublic
Target Version:0.2.5
Summary:Against adding the same image to favorites twice
Description:In a nutshell, the flood control might not be working properly. The system, somehow, let me to add multiple images at once. You can verify it by yourself by checking out my favorites (quick link bellow).

I remember Gelbooru seemingly being under very heavy load (or my internet connection being bad) and I was pressing 'Add to Favorites' multiple times before the 'This post is already in your favorites!' started appearing, which is probably the origin of this issue (although I'm unable to reproduce it now.)

This is a very large vulnerability, especially if this kind of issue applies to comments as well, cause an attacker can spam AJAX requests and inject dozens of posts before the flood control comes to its senses, making the attack a dozen times more efficient.

Link to my favorites:
Additional Info:No additional information.