json-parsing

1 article
sort: new top best
clear filter
0 7/10

A site-wide CSRF vulnerability was discovered on a popular program where the backend accepted form-encoded payloads (application/x-www-form-urlencoded) despite expecting JSON, because the server failed to strictly validate the Content-Type header. The attacker bypassed the false assumption that JSON-only handling would prevent CSRF by sending traditional form-based CSRF payloads.

Ajinkya Pathare
fellchase.blogspot.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details