Web Hack List

Other nomination

Exploiting Client-Side Path Traversal to Perform Cross-Site Request Forgery - Introducing CSPT2CSRF

Attacker-controlled input in a URL fragment, query or stored record traverses the path a front end builds for its own API call, rerouting the authenticated request to a different endpoint. That revives CSRF despite SameSite cookies, and a GET-sink primitive can be chained through a file upload gadget into state-changing POST or DELETE calls.

Record

Researcher
Maxence Schmitt

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Maxence Schmitt, first published at the original source. Preserved copies are kept so the citation survives its host.