Other nomination
Exploiting Client-Side Path Traversal to Perform Cross-Site Request Forgery - Introducing CSPT2CSRF
Attacker-controlled input in a URL fragment, query or stored record traverses the path a front end builds for its own API call, rerouting the authenticated request to a different endpoint. That revives CSRF despite SameSite cookies, and a GET-sink primitive can be chained through a file upload gadget into state-changing POST or DELETE calls.
Record
- Researcher
- Maxence Schmitt
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Maxence Schmitt, first published at the original source. Preserved copies are kept so the citation survives its host.