Account Takeover using Linked Accounts due to lack of CSRF protection
High
R
Rockstar Games
Submitted None
Team Summary
Official summary from Rockstar Games
In this report, the researcher found a weakness in our third-party account linking process. They were able to create a malicious link that, if clicked by the victim, would under certain conditions give the attacker access to the victim's Social Club account. This issue has now been fixed.
Actions:
Reported by
rafiem
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-Site Request Forgery (CSRF)