Loading HuntDB...

CSRF that makes any user send invitations to the attacker by simply clicking on a link.

Medium
L
LinkedIn
Submitted None

Team Summary

Official summary from LinkedIn

The researcher found a CSRF issue that allowed targeted links (intended and usable only by a single member) to send connection invitations once clicked on without any prompt/intermediary step to confirm such action. Thank you @marvelmaniac for the report!

Reported by marvelmaniac

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-Site Request Forgery (CSRF)