Loading HuntDB...

Cross-Site WebSocket Hijacking Lead to Steal XSRF-TOKEN

High
S
Stripo Inc
Submitted None

Team Summary

Official summary from Stripo Inc

The WebSocket handshake request was vulnerable to CSRF, WebSocket content was contain many sensitive data for the user

Reported by 0xwise

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic