Loading HuntDB...

[CSRF] No Csrf protection against sending invitation to join the team.

Medium
L
Lark Technologies
Submitted None

Team Summary

Official summary from Lark Technologies

A Cross-Site Request Forgery (CSRF) vulnerability was found on a "Create Invite" endpoint, which could result in any users being added to a team by tricking another user to run this Proof of Concept. We thank @imran_nisar for reporting this to our team.

Reported by imran_nisar

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-Site Request Forgery (CSRF)