Loading HuntDB...

No CSRF protection when adding an item to cart

Low
M
Mars
Submitted None

Team Summary

Official summary from Mars

The given report highlights a security vulnerability in a web application. Specifically, a state-changing POST request to "██████" lacks proper authentication, making it susceptible to Cross-Site Request Forgery (CSRF) attacks. This means that an attacker could manipulate users into unknowingly and involuntarily triggering sensitive actions on the website. The absence of proper authentication opens up the possibility of unauthorized and malicious exploitation of the web application.

Reported by themarkib0x0

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-Site Request Forgery (CSRF)