CSRF at Network feature
Medium
L
Lichess
Submitted None
Actions:
Reported by
psfauzi
Vulnerability Details
Technical details and impact analysis
## Summary:
A csrf vulnerability was found in the network feature, where an attacker can change Network Routing settings by sending a csrf script to the victim.
## Steps To Reproduce:
1. Prepare the csrf script as below.
```
<html><body><a href="https://lichess.org/account/network?usingAltSocket=false">click</a></script></body></html>
```
2. save the script above to your server. for example csrf.html
3. send to the victim registered in the Lichess application
Proof :
Victim set Network Routing feature to ==Use CDN Routing==:
{F4509912}
Attacker sent csrf to victim:
{F4509921}
Victim visit the csrf link then pressing the click button from the csrf that the attacker sent
{F4509929}
* [attachment / reference]
{F4509951}
## Impact
An irresponsible malicious user can change network routing settings by sending a csrf script to the victim.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-Site Request Forgery (CSRF)