Loading HuntDB...

CSRF in cancel group and private show requests

Medium
C
Chaturbate
Submitted None

Team Summary

Official summary from Chaturbate

The hacker found that the private and group show cancel urls were not checking for CSRF headers. This issue was quickly resolved.

Reported by encrypt

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$300.00

Submitted

Weakness

Cross-Site Request Forgery (CSRF)