cross-site-request-forgery

2 articles
Sort: New Top Best
clear filter
0

A CSRF vulnerability was discovered in a web application's address deletion feature that lacked CSRF token protection, compounded by a predictable numeric addressId parameter that could be brute-forced via JavaScript to delete arbitrary user addresses. The researcher developed a proof-of-concept that sends hundreds of requests with sequential addressId values from a victim's browser to identify and delete their saved addresses.

Smaran Chand Nittam xyzcompany.com
smaranchand.com.np · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
vulnerability

Site-wide CSRF vulnerability discovered on Messenger.com where CSRF token (fb_dtsg) validation was completely missing on multiple endpoints, allowing attackers to perform unauthorized actions like changing settings and removing users from group threads. The vulnerability affected all POST requests regardless of whether the token was modified, removed, or omitted entirely.

messenger.com Facebook @phwd @mazen160 fb_dtsg XMessengerDotComSettingsEditController
whitton.io · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details