Web Hack List

Other nomination

CSRF with JSON -- leveraging XHR and CORS

Shows CSRF surviving JSON APIs: an XHR-Level 2 request with withCredentials true and Content-Type text/plain adds no custom header, so CORS skips the preflight, the browser replays the victim's cookies, and a server that never checks Content-Type processes the JSON body. Screenshots of the script, the wire request and the JSON response carry the proof.

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.