CSRF that makes any user send invitations to the attacker by simply clicking on a link.
Medium
L
LinkedIn
Submitted None
Team Summary
Official summary from LinkedIn
The researcher found a CSRF issue that allowed targeted links (intended and usable only by a single member) to send connection invitations once clicked on without any prompt/intermediary step to confirm such action. Thank you @marvelmaniac for the report!
Actions:
Reported by
marvelmaniac
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-Site Request Forgery (CSRF)