csrf

60 articles
Sort: New Top Best
clear filter
0
blog.darabi.me · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
vulnerability
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
vulnerability
blog.darabi.me · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
ahussam.me · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
josipfranjkovic.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
vulnerability

A CSRF vulnerability in Facebook's Instagram Business Tools allowed attackers to execute arbitrary GraphQL mutations by crafting malicious URLs that leveraged the victim's authenticated access token, enabling unauthorized actions like creating posts with malicious content. The vulnerability exploited improper parameter handling in the /business/:id endpoint where user-controlled IDs were sent to the Graph API without proper CSRF protections.

Facebook Instagram business.instagram.com graph.facebook.com BusinessToolsEntrypoint.instagram BusinessStore.instagram SyncAddMutations
philippeharewood.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
vulnerability
rafiem.github.io · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
santuysec.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0

A CSRF vulnerability was discovered in a web application's address deletion feature that lacked CSRF token protection, compounded by a predictable numeric addressId parameter that could be brute-forced via JavaScript to delete arbitrary user addresses. The researcher developed a proof-of-concept that sends hundreds of requests with sequential addressId values from a victim's browser to identify and delete their saved addresses.

Smaran Chand Nittam xyzcompany.com
smaranchand.com.np · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
soroush.secproject.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
vulnerability

Site-wide CSRF vulnerability discovered on Messenger.com where CSRF token (fb_dtsg) validation was completely missing on multiple endpoints, allowing attackers to perform unauthorized actions like changing settings and removing users from group threads. The vulnerability affected all POST requests regardless of whether the token was modified, removed, or omitted entirely.

messenger.com Facebook @phwd @mazen160 fb_dtsg XMessengerDotComSettingsEditController
whitton.io · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
nirmaldahal.com.np · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
vulnerability
medium.com · Mohamed Laajimi · 125 years ago · details
0
lokeshdlk77.medium.com · Lokesh kumar · 125 years ago · details
0
medium.com · Lokesh Kumar · 125 years ago · details
0
ysamm.com · Samm0uda · 125 years ago · details
0
rohitcoder.medium.com · Rohit kumar · 125 years ago · details
0
rohitcoder.medium.com · Rohit kumar · 125 years ago · details