Web Hack List

Other nomination

Multiple Facebook Messenger CSRF's

Two CSRF holes in messenger.com: the send_messages and delete_thread endpoints accepted cross-site POST requests without checking a token, so a page the victim visits could send messages from their account to any user or delete their message threads. Both were fixed by Facebook.

Record

Researcher
Mazin Ahmed and @mazen160
Published by
Mazin Ahmed

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Mazin Ahmed and @mazen160, first published at the original source. Preserved copies are kept so the citation survives its host.