Loading HuntDB...

CSRF with redeem coupon request

I
Instacart
Submitted None

Team Summary

Official summary from Instacart

This behavior is working as intended. We have a number of fraud prevention mechanisms in place that limit the effects of a single entity abusing this feature.

Reported by introvertmac

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted

Weakness

Cross-Site Request Forgery (CSRF)