CSRF account-email takeover by exploiting broken token validation
The change-email form has an anti-CSRF token, but the server ignores the parameter if you delete it. That turns a protected form into a one-click account takeover.
The full write-up is locked
Unlock the step-by-step write-up, screenshots and PoC file by purchasing this listing.
The change-email form has an anti-CSRF token, but the server ignores the parameter if you delete it. That turns a protected form into a one-click account takeov...…
Browse the file tree freely — unlock to download.
-
csrf_change_email.html 0.6 KB
CSRF labs
View all labsReviews & Questions
Sign in to ask a question or leave a review.
No reviews or questions yet — be the first.
Listing Details
- Author
- cyber_ghost
- Published
- 2026-09-13
- Target / OS
- Change-email endpoint with a CSRF token that is only checked when present
- Category
- Web Apps
- Payout Method
- No preference
Price
0.0120 BTC
≈ $780.00
Live Chat
Ask the seller or other buyers a question — mention someone with @handle
No messages yet — start the conversation.
Sign in to join the conversation.