Web Apps Vendor: cyber_ghost

CSRF account-email takeover by exploiting broken token validation

The change-email form has an anti-CSRF token, but the server ignores the parameter if you delete it. That turns a protected form into a one-click account takeover.

The full write-up is locked

Unlock the step-by-step write-up, screenshots and PoC file by purchasing this listing.

The change-email form has an anti-CSRF token, but the server ignores the parameter if you delete it. That turns a protected form into a one-click account takeov...…

Browse the file tree freely — unlock to download.

  • csrf_change_email.html 0.6 KB

Reviews & Questions

Sign in to ask a question or leave a review.

No reviews or questions yet — be the first.

Listing Details

Author
cyber_ghost
Published
2026-09-13
Target / OS
Change-email endpoint with a CSRF token that is only checked when present
Category
Web Apps
Payout Method
No preference

Price

0.0120 BTC

≈ $780.00

Live Chat

Ask the seller or other buyers a question — mention someone with @handle

Sign in to join the conversation.