[CSRF] No Csrf protection against sending invitation to join the team.
Medium
L
Lark Technologies
Submitted None
Team Summary
Official summary from Lark Technologies
A Cross-Site Request Forgery (CSRF) vulnerability was found on a "Create Invite" endpoint, which could result in any users being added to a team by tricking another user to run this Proof of Concept. We thank @imran_nisar for reporting this to our team.
Actions:
Reported by
imran_nisar
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-Site Request Forgery (CSRF)