Loading HuntDB...

CSRF Vulnerability on post creation page /community/create-post.json

Low
R
Rockstar Games
Submitted None

Team Summary

Official summary from Rockstar Games

In this report the researcher demonstrated how to exploit a CSRF vulnerability on the impacted endpoint. This would allow a remote attacker to spam the community boards as other users. This attack only worked in Chrome browsers. A recent update to Chrome changed how cross-origin requests are handled, and as a result this attack is no longer exploitable in modern browsers.

Reported by netfuzzer

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-Site Request Forgery (CSRF)