post-to-get

1 article
sort: new top best
clear filter
0 7/10

A CSRF protection bypass technique achieved by converting a POST request with a valid _csrf token to a GET request and removing the token parameter, exploiting improper server-side validation that only checks tokens on POST requests. The attacker uses JavaScript to automatically redirect victims without user interaction.

Yeasir Arafat
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details