token-validation

1 article
Sort: New Top Best
clear filter
0
vulnerability

Site-wide CSRF vulnerability discovered on Messenger.com where CSRF token (fb_dtsg) validation was completely missing on multiple endpoints, allowing attackers to perform unauthorized actions like changing settings and removing users from group threads. The vulnerability affected all POST requests regardless of whether the token was modified, removed, or omitted entirely.

messenger.com Facebook @phwd @mazen160 fb_dtsg XMessengerDotComSettingsEditController
whitton.io · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details