post-based-csrf

1 article
sort: new top best
clear filter
0 6/10

CVE-2017-10711 is a reflected XSS vulnerability in SimpleRisk's password reset form where the 'user' parameter is echoed directly without sanitization, allowing attackers to execute arbitrary JavaScript and potentially hijack user sessions through POST-based CSRF attacks.

CVE-2017-10711 SimpleRisk Mohamed A. Baset reset.php Mozilla Public License
seekurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 12 hours ago · details