Skip to content

Add category for Flash-based CSRF #280

@hakluke

Description

@hakluke

We have multiple XSS categories including a P4 flash-based XSS category, but we have not done the same with CSRF.

I recommend a P4 flash-based CSRF category for the old 307 redirect trick.

https://blog.appsecco.com/exploiting-csrf-on-json-endpoints-with-flash-and-redirects-681d4ad6b31b

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions