html-form-attack

1 article
sort: new top best
clear filter
0 7/10

A JSON-based CSRF vulnerability was discovered on Badoo's mobile site (m.badoo.com) allowing attackers to perform account deletion and contact erasure without CSRF tokens by leveraging HTML form submissions with text/plain encoding to bypass JSON content-type restrictions. The researcher crafted HTML forms that automatically execute privileged API actions when visited by authenticated victims, resulting in a $280 bounty.

Sahil Tikoo Badoo HackerOne m.badoo.com Burpsuite
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details