Web Hack List

Other nomination

NODE.JS CONNECT CSRF BYPASS ABUSING METHODOVERRIDE MIDDLEWARE

In Node.js Connect and Express, middleware runs in declaration order, so registering csrf before methodOverride lets an attacker send a GET request carrying _method=POST or an x-http-method-override header. The CSRF middleware skips token checks on idempotent verbs, then methodOverride upgrades the request to POST, executing a state-changing action with no token.

Record

Published by
blog.nibblesec.org

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of blog.nibblesec.org, first published at the original source. Preserved copies are kept so the citation survives its host.