Loading HuntDB...

CSRF in "send them an email and browser notification" feature

Low
C
Chaturbate
Submitted None

Team Summary

Official summary from Chaturbate

The hacker found that the "send an email and browser notification" feature was a GET call and did not check for csrf tokens, this was resolved.

Reported by encrypt

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$150.00

Submitted

Weakness

Cross-Site Request Forgery (CSRF)