server-side-validation

2 articles
sort: new top best
clear filter
0 7/10

A researcher discovered a P1 account takeover vulnerability by bypassing CSRF protections on a password change endpoint through server-side validation bypass—using a random email address format instead of the victim's actual email allowed successful password changes without requiring the victim's email in the CSRF payload.

Lady Secspeare Bugcrowd
ladysecspeare.wordpress.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 6/10

Researcher discovered a CSRF vulnerability in an e-commerce website where the form_key token lacked server-side validation, allowing an attacker to forge requests to add arbitrary addresses to victim accounts. The vulnerability was successfully demonstrated by removing the token from a CSRF PoC payload, resulting in a $500 bounty.

Rajesh Ranjan Bugcrowd form_key
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details