CSRF in "send them an email and browser notification" feature
Low
C
Chaturbate
Submitted None
Team Summary
Official summary from Chaturbate
The hacker found that the "send an email and browser notification" feature was a GET call and did not check for csrf tokens, this was resolved.
Actions:
Reported by
encrypt
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$150.00
Submitted
Weakness
Cross-Site Request Forgery (CSRF)